HackingVulnerability ExploitStolen CredentialsTargetedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Vista Higher Learning
bd_c9778375a87749c8 · schema v1 · pii pii-v1
Full breach record for Vista Higher Learning →Vista Higher Learning, Inc. disclosed a cyberattack beginning July 10, 2024, where a cybercriminal exploited a vulnerability to access network files. The incident affected a small number of individuals, exposing names, Social Security Numbers, and bank account information. VHL engaged Rapid7 for investigation and remediation, including server isolation and MDR implementation. 24 months of identity theft protection were offered.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7191ed8772961ad2Indiana State AGfiled 2024-09-06Verified
- bd_8ea69603340c9918New Hampshire State AGfiled 2024-09-06Verified
- bd_8fd8045d61c60fe9Maine State AGfiled 2024-09-06Candidate
- bd_a9ec4e93ab19bc05Montana State AGfiled 2024-09-06Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-06-vista-higher-learning-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 6, 2024
- Raw hash
- 3b183065479b8a9bb0d3d897e5ae6e067741e0d774832ee5bd7ed2b6aba749b0
Reporting entity
- Name
- Vista Higher Learningnorm: vista higher learning
Victim entity
- Name
- Vista Higher Learningnorm: vista higher learning
Incident
- Discovered
- Jul 23, 2024
- Materiality determined
- —
- Notification sent
- Sep 6, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying relevant state authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.