HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTMediumActive
University of New Mexico Foundation
bd_dd40ef1c30c41441 · schema v1 · pii pii-v1
Full breach record for University of New Mexico Foundation →The University of New Mexico Foundation disclosed that an unauthorized individual gained access to its network via a security services provider account in mid-April 2017. Affected data included names, contact info, SSNs, bank account/routing numbers, and employment data for donors and employees. The investigation was ongoing at the time of notification. Credit monitoring was offered.
California clockDiscovered Apr 15, 2017 → Notified May 15, 201730d ✓ CA 60-day OK4 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0ae2ea77c4e0a489Montana State AGfiled 2017-05-15Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-68867
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2017
- Raw hash
- b89178be82d352003df16e9be94ae3964b1b750a9824970529a14498521512dd
Reporting entity
- Name
- University of New Mexico Foundationnorm: university of new mexico
Victim entity
- Name
- University of New Mexico Foundationnorm: university of new mexico
Incident
- Discovered
- Apr 15, 2017
- Materiality determined
- —
- Notification sent
- May 15, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to federal law enforcement
- Third party
- via security services provider
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 15, 2017→ Notified: May 15, 201730d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.