MalwareRansomwareData ExfiltratedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Northwest Arkansas Community College
bd_d768e4b42ce79977 · schema v1 · pii pii-v1
Full breach record for Northwest Arkansas Community College →Northwest Arkansas Community College (NWACC) experienced a ransomware attack in July 2024. The incident resulted in the potential exfiltration of personal information, including names, addresses, SSNs, driver's license numbers, government IDs, financial account information, and dates of birth. NWACC notified law enforcement, engaged cybersecurity specialists, and implemented remediation measures including global password resets and endpoint detection. 27 Maryland residents were notified and offered 12 months of credit monitoring.
Maryland clock✗ MD AG >90d34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d2191078372fbaceIndiana State AGfiled 2025-02-27Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376428.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- 3bb47959123182a42894064700a4015961e3f1b0987eae72ec90fc2d3dfdc6ee
Reporting entity
- Name
- Northwest Arkansas Community Collegenorm: northwest arkansas community college
Victim entity
- Name
- Northwest Arkansas Community Collegenorm: northwest arkansas community college
Incident
- Discovered
- Jul 1, 2024
- Materiality determined
- —
- Notification sent
- Feb 27, 2025
- Affected individuals
- 27
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.