Social EngineeringPhishingStolen CredentialsMulti-Stage ChainData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICAUTHENTICATIONLowContained
Simmons University Homepage
bd_c4eddb1389b4b7ff · schema v1 · pii pii-v1
Full breach record for Simmons University Homepage →Simmons University reported a phishing incident on March 14, 2025, affecting one New Hampshire resident. The breach occurred on March 9, 2025, when an employee clicked a malicious link and provided credentials, allowing unauthorized access to WorkDay. PII was exfiltrated. The incident was contained on March 10. Remediation included account lockdown, forensic investigation, and credit monitoring for the victim.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/simmons-university-20250314.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2025
- Raw hash
- fd3e8c410e6ab30afed31c618e071c63a4719e120c4da7c0173508d87bf2771b
Reporting entity
- Name
- Simmons University Homepagenorm: simmons university homepage
- Domain
- simmons.edu
Victim entity
- Name
- Simmons University Homepagenorm: simmons university homepage
- Domain
- simmons.edu
Incident
- Discovered
- Mar 10, 2025
- Materiality determined
- —
- Notification sent
- Mar 11, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICAUTHENTICATION
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 days(4 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.