HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Georgia Institute of Technology
bd_8a1d9df1eb51d81f · schema v1 · pii pii-v1
Full breach record for Georgia Institute of Technology →Georgia Institute of Technology disclosed a security incident where an unauthorized party accessed an internal database via a web server. Access occurred between Dec 14, 2018, and Mar 22, 2019. Affected data included names, addresses, Institute IDs, DOBs, and SSNs. Georgia Tech engaged forensic firms, secured the server, and offered one year of credit monitoring via ID Experts. The incident was reported to the U.S. Department of Education.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/09/GT_Sample_Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 13, 2019
- Raw hash
- ee91f7a0d9d3175a14ef01f8f89658f7acec929a882c9d3a62a1b4be3797a2da
Reporting entity
- Name
- Georgia Institute of Technologynorm: georgia institute of
Victim entity
- Name
- Georgia Institute of Technologynorm: georgia institute of
Incident
- Discovered
- Mar 1, 2019
- Materiality determined
- —
- Notification sent
- May 15, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified the U.S. Department of Education
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(165 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.