HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Princeton University
bd_ced3f5a433764e98 · schema v1 · pii pii-v1
Full breach record for Princeton University →Princeton University disclosed a data breach where former student records, including SSNs and dates of birth, were exposed on a public website. The exposure began on April 28, 2020, and was discovered on June 6, 2022. Princeton removed the files, engaged a third-party cybersecurity firm, and provided two years of identity monitoring via Kroll to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_adfb38a8d099d07eMaine State AGfiled 2022-07-08Verified
- bd_513f9ba541db089cMontana State AGfiled 2022-07-11(3d gap)Verified
- bd_22b3205bc6ac1e26Maine State AGfiled 2022-06-28(10d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555062
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2022
- Raw hash
- 878e946aafda96e4e4df0c457dfeea7d69514e1af60e03faab95ef059bc2e3f1
Reporting entity
- Name
- Princeton Universitynorm: princeton university
- Domain
- princeton.edu
Victim entity
- Name
- Princeton Universitynorm: princeton university
- Domain
- princeton.edu
Incident
- Discovered
- Jun 6, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.