Social EngineeringPhishingTargetedPIIIDENTITY_BASICLowContained
National University of Natural Medicine
bd_99008cb8d07aec6b · schema v1 · pii pii-v1
Full breach record for National University of Natural Medicine →National University of Natural Medicine notified consumers of a cybersecurity incident where an unauthorized individual accessed an employee email account between July 22 and July 29, 2025. The incident likely involved personal information. The university secured the account, engaged external forensic investigators, and is offering complimentary identity monitoring services through Kroll.
Vermont clock✗ VT AG >45 bday17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0d18555132480751Indiana State AGfiled 2025-11-26Verified
- bd_1b06caf98ea5bd8fMaine State AGfiled 2025-11-26Candidate
- bd_b2a8e852202dea7dOregon State AGfiled 2025-11-26Verified
- bd_bb50dd7193281f83Montana State AGfiled 2025-11-26Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_1bd53a3a48ee1fcfNew Hampshire State AGfiled 2025-12-01(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-26-national-university-natural-medicine-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2025
- Raw hash
- 0fe4829ec967ab2336b9ac899f3745de6dc37205b1afa09e9ebadc61cf7a3452
Reporting entity
- Name
- National University of Natural Medicinenorm: national university of natural medicine
Victim entity
- Name
- National University of Natural Medicinenorm: national university of natural medicine
Incident
- Discovered
- Jul 29, 2025
- Materiality determined
- Nov 7, 2025
- Notification sent
- Nov 26, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(120 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.