Campus CE Corporation
bd_850103eaf941d4b6 · schema v1 · pii pii-v1
Full breach record for Campus CE Corporation →Campus CE Corporation, a provider of software tools for educational institutions, disclosed a data security incident involving a misconfigured PeopleSoft log permission setting. The vulnerability potentially allowed unauthorized access to student data (names, birthdates, addresses, emails, phone numbers, gender, ethnicity) from 2022 through July 25, 2024. The issue was detected on August 1, 2024, following a student report. Approximately 57,000 students were potentially affected, with 52,175 in Washington. No financial data or SSNs were involved. CampusCE engaged independent investigators and legal counsel, corrected the setting, and notified the Washington Attorney General.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2022
Begins
Aug 1, 2024
Discovered
Sep 13, 2024
Filed
vs. sector median
4 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.