HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Gaston College
bd_8dd8588b89e6f20b · schema v1 · pii pii-v1
Full breach record for Gaston College →Gaston College notified consumers of unauthorized network access occurring February 21-22, 2023. The incident involved the acquisition of files containing personal information. Gaston College engaged the NC Joint Cybersecurity Task Force and third-party specialists for investigation and remediation. Affected individuals were offered 12 months of identity monitoring via Kroll. The specific data elements accessed were redacted in the public notice template.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by nokoyawa about this victim predates this filing by 168 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_398ba9c747a25eb2Leak Sitenokoyawafiled 2023-03-09(169d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_115feb0035c68f6aMontana State AGfiled 2023-08-28(3d gap)Verified
- bd_f4c0d005bff0a19aMaine State AGfiled 2023-08-29(4d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-25-gaston-college-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- 73d99d85012e790f47cf34bf6ece1ade3ddf159a869fc518588f466c1e8c223b
Reporting entity
- Name
- Gaston Collegenorm: gaston college
- Domain
- gaston.edu
Victim entity
- Name
- Gaston Collegenorm: gaston college
- Domain
- gaston.edu
Incident
- Discovered
- Feb 22, 2023
- Materiality determined
- Aug 25, 2023
- Notification sent
- Aug 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- assistance from the North Carolina Joint Cybersecurity Task Force
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(184 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.