HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
TRUSTEES OF DARTMOUTH COLLEGE
bd_d741e94ef055d19f · schema v1 · pii pii-v1
Full breach record for TRUSTEES OF DARTMOUTH COLLEGE →Dartmouth College notified the California AG of a data breach involving its Oracle eBusiness Suite software. An unauthorized actor exploited a zero-day vulnerability to exfiltrate files between August 9 and August 12, 2025. The stolen data included names, Social Security numbers, and financial account information. Dartmouth secured the environment, notified law enforcement, applied patches, and offered one year of identity monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_38e52b6e38cc0ee4Indiana State AGfiled 2025-11-24Verified
- bd_3b0210c2acc1ce1bMontana State AGfiled 2025-11-24Candidate
- bd_e56966dbdaa7a6aaNew Hampshire State AGfiled 2025-11-24Verified
- bd_f2c4dd09e711cb7cVermont State AGfiled 2025-11-24Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614718
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 24, 2025
- Raw hash
- d51ed0434e0815c4b99c3b5f76c5ee4b4175de21b7d9c0f52ec60a935fcadb47
Reporting entity
- Name
- TRUSTEES OF DARTMOUTH COLLEGEnorm: trustees of dartmouth college
- Domain
- dartmouth.edu
Victim entity
- Name
- TRUSTEES OF DARTMOUTH COLLEGEnorm: trustees of dartmouth college
- Domain
- dartmouth.edu
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 24, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.