The Curators of the University of Missouri
bd_9e9feecb13b05e12 · schema v1 · pii pii-v1
Full breach record for The Curators of the University of Missouri →The University of Missouri notified the New Hampshire Attorney General on October 25, 2023, of a data breach involving approximately 29 NH residents. The incident stemmed from a zero-day vulnerability in Progress Software's MOVEit Transfer application, disclosed by Progress on May 31, 2023. The University confirmed that personal information of affected individuals was acquired by unauthorized actors. The University engaged third-party experts, notified law enforcement, took the application offline, applied patches, and offered two years of Kroll identity monitoring services. The investigation concluded on September 9, 2023.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3a959c98420de3f4California State AGfiled 2023-10-25Verified
- bd_c3de8a40450c33a3Maine State AGfiled 2023-10-24(1d gap)Candidate
- bd_441790aaefd4d414Vermont State AGfiled 2023-10-20(5d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/university-missouri-20231025.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2023
- Raw hash
- d6e61e5238bdcb3ac67a5afc6f6c463b66e8835df29d24a7dd812733e22e0df3
Reporting entity
- Name
- The Curators of the University of Missourinorm: the curators of the university of missouri
Victim entity
- Name
- The Curators of the University of Missourinorm: the curators of the university of missouri
Incident
- Discovered
- Sep 9, 2023
- Materiality determined
- —
- Notification sent
- Oct 20, 2023
- Affected individuals
- 29
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.