HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Anne Arundel Community College
bd_8a6014521905bbdb · schema v1 · pii pii-v1
Full breach record for Anne Arundel Community College →Anne Arundel Community College (AACC) disclosed a security incident on Feb 14, 2025, where a student accessed another student's profile in the Lifelong Learning Extended Education (LLEE) system. The unauthorized access was caused by an admin cross-connecting accounts during deduplication. Compromised data included names, addresses, AACC IDs, and partial credit card info. No SSNs or full card numbers were exposed. AACC notified regulators and offered 1 year of credit monitoring.
Maryland clock✓ MD AG ≤30d5 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376375.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2025
- Raw hash
- fa1939af794d3d2c361ea3851595ee91ada802406cc6a8b336a9348f061e30c7
Reporting entity
- Name
- Anne Arundel Community Collegenorm: anne arundel community college
- Domain
- aacc.edu
Victim entity
- Name
- Anne Arundel Community Collegenorm: anne arundel community college
- Domain
- aacc.edu
Incident
- Discovered
- Feb 14, 2025
- Materiality determined
- —
- Notification sent
- Feb 20, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified the Department of EducationNotified Maryland Office of Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- MD AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.