HackingEducationEducationVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIILowResolved
LEE UNIVERSITY
bd_d5f5a1eec1591b7c · schema v1 · pii pii-v1
Full breach record for LEE UNIVERSITY →In March 2024, Lee University experienced a security incident involving a third-party software vulnerability that allowed unauthorized access to university systems and potential downloading of university data. A comprehensive data review concluded in March 2025. Notification letters were sent to affected individuals on March 24, 2025, offering IDX identity protection services. The incident involved PII of an unspecified number of individuals.
Leak gap clock✗ Leak >180d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 5 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 342 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_96bc7c394d2c81b3Washington State AGfiled 2025-03-26Candidate
- bd_b3e570950a87e26fWashington State AGfiled 2025-03-26Candidate
- bd_daa4525b9e17e7ccVermont State AGfiled 2025-03-24(2d gap)Verified
- bd_f58b3272065c16f6Indiana State AGfiled 2025-03-24(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600391
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2025
- Raw hash
- e2d3f231e0bb56b9146f7adb4b152bebdca9626b96abacd548f930fcdc1b8e68
Reporting entity
- Name
- LEE UNIVERSITYnorm: lee university
Victim entity
- Name
- LEE UNIVERSITYnorm: lee university
- Industry
- Educationllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 24, 2025
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- Leak >180d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.