HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSHighContained
Paul Quinn College
bd_85f80ebb40f44b7b · schema v1 · pii pii-v1
Full breach record for Paul Quinn College →Paul Quinn College notified the California Attorney General of a data security incident involving unauthorized access to employee email accounts starting May 24, 2019. The breach exposed personal information including SSNs, driver's license numbers, financial account info, and medical data for 1,159 California residents. Notifications were sent on June 1, 2020, offering 12 months of credit monitoring.
California clockDiscovered Aug 16, 2019 → Notified Jun 1, 2020290d ✗ CA 60-day late41 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_38a0f94f5617a990Montana State AGfiled 2020-06-01Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190540
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2020
- Raw hash
- 2604ac9d36a583c074b01212c88ee3baa115bfdf24b658ef83d8768f4b895496
Reporting entity
- Name
- Paul Quinn Collegenorm: paul quinn college
Victim entity
- Name
- Paul Quinn Collegenorm: paul quinn college
Incident
- Discovered
- Aug 16, 2019
- Materiality determined
- Jun 1, 2020
- Notification sent
- Jun 1, 2020
- Affected individuals
- 1,159
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Submitted notification to California Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(290 days from discovery to filing)
- Compliance flags
- CA 60-day late · 290d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 16, 2019→ Notified: Jun 1, 2020290d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.