MalwareRansomwareData ExfiltratedData EncryptedTargetedIDENTITY_BASICLowContained
Bunker Hill Community College
bd_88222e97df170fef · schema v1 · pii pii-v1
Full breach record for Bunker Hill Community College →Bunker Hill Community College experienced a ransomware attack in May 2023. An unauthorized actor gained network access, deployed ransomware, and copied a limited amount of data. The incident was contained. Data types affected include names and other personal information. BHCC engaged forensic experts, contacted law enforcement, reset passwords, and offered 24 months of credit monitoring.
Vermont clock✗ VT AG >45 bday31 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by snatch about this victim predates this filing by 198 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_81b8c46daafd0abdLeak Sitesnatchfiled 2023-06-14(198d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_6b00e50e35e53affMaine State AGfiled 2023-12-29Verified by operator
- bd_9e1c1004db6121b5Montana State AGfiled 2023-12-29Verified by operator
- bd_9f5c133fc96fca16California State AGfiled 2023-12-29Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-29-bunker-hill-community-college-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 29, 2023
- Raw hash
- 467b0bce209cbf0f97d15ab2a179a94dcc07628e07a0f11d365786f53b54b49a
Reporting entity
- Name
- Bunker Hill Community Collegenorm: bunker hill community college
Victim entity
- Name
- Bunker Hill Community Collegenorm: bunker hill community college
Incident
- Discovered
- May 23, 2023
- Materiality determined
- Dec 29, 2023
- Notification sent
- Dec 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this Incident to relevant government agencies and law enforcement
Compliance
- Time to disclose
- 31 weeks(220 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.