HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
University of the People
bd_970e1ff5835dd356 · schema v1 · pii pii-v1
Full breach record for University of the People →University of the People reported unauthorized access to its SharePoint platform between Jan 2-10, 2022. The incident impacted 19 New Hampshire residents' PII. UoPeople engaged forensic experts, notified law enforcement, changed passwords, and offered credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_57d53b879077ad26Vermont State AGfiled 2023-04-04Verified
- bd_7684067d9ceb71f9Montana State AGfiled 2023-04-04Candidate
- bd_1d855dd1d17c87fbCalifornia State AGfiled 2023-04-05(1d gap)Verified
- bd_ac9b991feced758eMaine State AGfiled 2023-04-05(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/university-people-20230404.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2023
- Raw hash
- bec55730f24ad2693bdedb204f7dd51ccb059213a22b8ff706059b8880d4232c
Reporting entity
- Name
- University of the Peoplenorm: university of the people
Victim entity
- Name
- University of the Peoplenorm: university of the people
Incident
- Discovered
- Jan 15, 2022
- Materiality determined
- —
- Notification sent
- Mar 24, 2023
- Affected individuals
- 19
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 months(444 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.