DisclosureLens
HackingEducationEducationVulnerability ExploitCapture Stored DataClopZero-DayData ExfiltratedSupply Chain (3P Vendor)TargetedRansom DemandedIdentity (basic)Government IDHighContained

The Board of Governors of the Colorado State University System

bd_d5be50961858899d · schema v1 · pii pii-v1

Severity

High

Discovered

Jul 10, 2023

Filed

Aug 16, 2023

To disclose

5 weeks

Affected · nationwide

19,34492 in this filing

Linked

2 filings

Confidence

67%
Full breach record for The Board of Governors of the Colorado State University System

The Colorado State University System (CSU) notified Montana regulators of a security event involving third-party vendors Pension Benefits Information (PBI) and the National Student Clearinghouse (NSC). The Russian threat actor Clop exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data including names and Social Security numbers. While CSU's own systems were not directly affected, 19,344 individuals whose data was held by vendors on behalf of CSU were impacted, including 92 Montana residents. CSU and vendors are providing two years of credit monitoring.

Incident timeline

undetected · 42 days
discovery → filing · 5 weeks / 37 days

May 29, 2023

Begins

Jul 10, 2023

Discovered

Aug 16, 2023

Filed

vs. sector median

2 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Montana State AGAug 16 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.