DisclosureLens
HackingEducationEducationVulnerability ExploitData ExfiltratedDelayed DiscoveryCustomer Data InvolvedIdentity (basic)Government IDMediumContained

California State University East Bay

bd_97b5f2bf6d39667d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 17, 2018

Filed

Oct 12, 2018

To disclose

25 days

Affected

Not disclosed

Linked

4 filings

Confidence

66%
Full breach record for California State University East Bay2 incidents on file

California State University East Bay disclosed that an unknown third-party exploited a vulnerability in a university web application to access and exfiltrate personal information, including names, addresses, and Social Security numbers. The unauthorized access occurred between March 27, 2017, and September 2, 2018, and was discovered on September 17, 2018. The university removed the compromised application, mitigated vulnerabilities, and offered 12 months of credit monitoring to affected individuals.

Incident timeline

undetected · 539 days
discovery → filing · 25 days

Mar 27, 2017

Begins

Sep 17, 2018

Discovered

Oct 12, 2018

Filed

vs. sector median

7 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Montana State AGOct 5 · first
California State AG+7d · this page

Pattern: first filing Oct 5 (MA), last Oct 12 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.