DisclosureLens
HackingEducationEducationVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedEducationEmploymentIdentity (basic)Government IDHighActive

Peninsula College

bd_de67e0bf4f97185c · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 16, 2023

Filed

Jul 28, 2023

To disclose

6 weeks

Affected

1,400state residents only

Confidence

69%
Full breach record for Peninsula College

Peninsula College notified WA AG of a third-party breach involving vendors NSC and TIAA using MOVEit Transfer software. Unauthorized access occurred around May 30, 2023. Student and employee PII, including SSNs, was potentially exposed. 1,400 WA residents affected. Investigation ongoing; credit monitoring offered.

Washington clock WA AG >30d6 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 17 days
discovery → filing · 6 weeks / 42 days

May 30, 2023

Begins

Jun 16, 2023

Discovered

Jul 28, 2023

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,400 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.