The Board of Governors of the Colorado State University System
bd_d5be50961858899d · schema v1 · pii pii-v1
Full breach record for The Board of Governors of the Colorado State University System →The Colorado State University System (CSU) notified Montana regulators of a security event involving third-party vendors Pension Benefits Information (PBI) and the National Student Clearinghouse (NSC). The Russian threat actor Clop exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data including names and Social Security numbers. While CSU's own systems were not directly affected, 19,344 individuals whose data was held by vendors on behalf of CSU were impacted, including 92 Montana residents. CSU and vendors are providing two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
Jul 10, 2023
Discovered
Aug 16, 2023
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGClopbd_442e2ef79000f25c2023-08-17 · +1dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.