Monmouth University
bd_99ed51db4805dd73 · schema v1 · pii pii-v1
Full breach record for Monmouth University →Monmouth University reported a data security incident to the New Hampshire Attorney General on June 30, 2026. An unauthorized third party accessed the university's network between February 5 and 13, 2026, exfiltrating files containing personal information of 217 New Hampshire residents. Data exposed included names, SSNs, driver's license numbers, financial account numbers, payment card info, and medical/health insurance data. Monmouth engaged forensic investigators, notified law enforcement, and is offering one year of complimentary credit monitoring to affected individuals.
Linked disclosures
Why this link?Ransomware claims (1)
- bd_2f9fdb38c91c7c57Leak Sitepearfiled 2026-03-03(119d gap)Verified by operator
Regulatory filings (6) · sorted by filing gap
- bd_346c38b67fb41663California State AGfiled 2026-06-30Verified
- bd_52b83bf7bc528fcdVermont State AGfiled 2026-06-30Verified
- bd_ea41c7a62f5cf428Delaware State AGfiled 2026-06-30Verified
- bd_a0056bdb614e9c6aTexas State AGfiled 2026-07-01(1d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 29d gap
- bd_2f2dd8dfe15aba32Massachusetts State AGfiled 2026-06-01(29d gap)Candidate
- bd_fda40e176e033c82Massachusetts State AGfiled 2026-06-01(29d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/monmouth-university-20260630.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2026
- Raw hash
- ffdec0fe99b29a081bd44f33d5736bf6fa7fa077c62b0c997c6632c7745e5606
Reporting entity
- Name
- Monmouth Universitynorm: monmouth university
- Domain
- monmouth.edu
Victim entity
- Name
- Monmouth Universitynorm: monmouth university
- Domain
- monmouth.edu
Incident
- Discovered
- Mar 3, 2026
- Materiality determined
- —
- Notification sent
- Jun 30, 2026
- Affected individuals
- 217
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.