HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
North Orange County Community College District
bd_a594205c18f354a0 · schema v1 · pii pii-v1
Full breach record for North Orange County Community College District →North Orange County Community College District (NOCCCD) issued a supplemental notice to the New Hampshire Attorney General regarding a cybersecurity incident affecting Cypress and Fullerton College networks. Unauthorized access occurred between December 7, 2021, and January 10, 2022. The breach impacted 3 New Hampshire residents, exposing names, SSNs, driver's license numbers, and financial account information. NOCCCD engaged forensic specialists, reported to the FBI, and provided 12 months of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_5bba2129dab58ac2California State AGfiled 2022-05-24(7d gap)Verified
- bd_08c4560773f95b7aCalifornia State AGfiled 2022-03-25(67d gap)Candidate
- bd_4c2cb50347a6bc30Maine State AGfiled 2022-03-25(67d gap)Verified
- bd_fb480a363c03778bMontana State AGfiled 2022-03-25(67d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/north-orange-county-20220531.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2022
- Raw hash
- b54d3ae7edde626e3c1f90e8426fa8e6f93ae748a499905a1a5294ae59bccf94
Reporting entity
- Name
- North Orange County Community College Districtnorm: north orange county community college district
- Domain
- nocccd.edu
- Industry
- Education
Victim entity
- Name
- North Orange County Community College Districtnorm: north orange county community college district
- Domain
- nocccd.edu
- Industry
- Education
Incident
- Discovered
- Jan 10, 2022
- Materiality determined
- —
- Notification sent
- May 24, 2022
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection BureauReported to FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.