HackingVulnerability ExploitData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LEE UNIVERSITY
bd_daa4525b9e17e7cc · schema v1 · pii pii-v1
Full breach record for LEE UNIVERSITY →Lee University notified consumers of a March 2024 data breach caused by a third-party software vulnerability. Attackers downloaded university data, potentially including names and government IDs. The university engaged cybersecurity experts, contained the incident, and offered 12-24 months of identity theft protection services. The investigation concluded in March 2025.
Vermont clock✗ VT AG >45 bday13 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 340 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_f58b3272065c16f6Indiana State AGfiled 2025-03-24Verified
- bd_96bc7c394d2c81b3Washington State AGfiled 2025-03-26(2d gap)Candidate
- bd_b3e570950a87e26fWashington State AGfiled 2025-03-26(2d gap)Candidate
- bd_d5f5a1eec1591b7cCalifornia State AGfiled 2025-03-26(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-24-lee-university-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2025
- Raw hash
- bd47d564675637eac731244daf3ce0ed6ac69b0a2367f9e4ca252f88a3533f59
Reporting entity
- Name
- LEE UNIVERSITYnorm: lee university
Victim entity
- Name
- LEE UNIVERSITYnorm: lee university
Incident
- Discovered
- Mar 1, 2024
- Materiality determined
- Mar 24, 2025
- Notification sent
- Mar 24, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 months(388 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.