HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
Paul Smith’s College
bd_bfee719da1d2219d · schema v1 · pii pii-v1
Full breach record for Paul Smith’s College →Paul Smith's College notified the NH Attorney General of unauthorized access to its network between July and August 2022. The incident affected approximately 145 New Hampshire residents (employees and students), exposing names, SSNs, and financial account information. The college secured its network, engaged outside cybersecurity professionals, and offered one year of credit monitoring to affected individuals.
Leak gap clock⏱ Leak >30d26 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed145 affectedView incident
A leak claim by avoslocker about this victim predates this filing by 57 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/paul-smiths-college-20230221.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2023
- Raw hash
- 3cd673b2477255faa620bdbe1c27dcbb2a18c8381a83958adc34eb43271226cf
Reporting entity
- Name
- Paul Smith’s Collegenorm: paul smith s college
Victim entity
- Name
- Paul Smith’s Collegenorm: paul smith s college
Incident
- Discovered
- Jan 26, 2023
- Materiality determined
- —
- Notification sent
- Feb 17, 2023
- Affected individuals
- 145
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Office of the Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.