California State University East Bay
bd_97b5f2bf6d39667d · schema v1 · pii pii-v1
Full breach record for California State University East Bay →2 incidents on fileCalifornia State University East Bay disclosed that an unknown third-party exploited a vulnerability in a university web application to access and exfiltrate personal information, including names, addresses, and Social Security numbers. The unauthorized access occurred between March 27, 2017, and September 2, 2018, and was discovered on September 17, 2018. The university removed the compromised application, mitigated vulnerabilities, and offered 12 months of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 27, 2017
Begins
Sep 17, 2018
Discovered
Oct 12, 2018
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- New Hampshire State AGbd_84245076a1e73af72018-10-08 · +4dVerified
- Massachusetts State AGbd_72d941280012d8422018-10-05 · +7dVerified
- Montana State AGbd_b8524b432e33abcd2018-10-05 · +7dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Oct 5 (MA), last Oct 12 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.