DisclosureLens
MalwareEducationEducationRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIIIdentity (basic)Government IDHighContained

R3 Education

bd_9e69937e0c530840 · schema v1 · pii pii-v1

Severity

High

Discovered

Nov 7, 2023

Filed

May 28, 2024

To disclose

29 weeks

Affected · nationwide

7,78518 in this filing

Linked

6 filings

Confidence

67%
Full breach record for R3 Education

R3 Education Inc. notified the New Hampshire Attorney General of a cybersecurity incident discovered on November 7, 2023. An unauthorized party gained access to systems, encrypted data (ransomware), and potentially exfiltrated information. The breach affected 7,785 individuals, including 18 New Hampshire residents (employees and students). Data types included names, SSNs, and DOBs. R3 engaged forensic investigators, reset credentials, and offered credit monitoring. Notices were mailed starting March 25, 2024.

Incident timeline

discovery → filing · 29 weeks / 203 days

Nov 7, 2023

Discovered

May 28, 2024

Filed

vs. sector median

+20 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 64d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Indiana State AGMar 25 · first
New Hampshire State AG+64d · this page

Pattern: first filing Mar 25 (IN), last May 28 (NH) — a 64-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.