Social EngineeringPhishingTargetedIDENTITY_BASICPIILowContained
Colorado State University - Pueblo
bd_e08271f0e5d8cffb · schema v1 · pii pii-v1
Full breach record for Colorado State University - Pueblo →Colorado State University – Pueblo notified consumers of a cybersecurity event on August 14, 2024, where employees were targeted by a social engineering attack. An unprotected Excel spreadsheet containing names, CSU ID numbers, and current billing balances was obtained by an unauthorized third party. No other systems were breached. The notice was filed with the Vermont Attorney General on September 4, 2024.
Vermont clock✓ VT AG ≤14 bday21 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_61c4d57e333de213Maine State AGfiled 2024-09-05(1d gap)Candidate
- bd_f5d8040d4a3cf6daNew Hampshire State AGfiled 2024-09-05(1d gap)Verified
- bd_4cbc52f0b9c4f0faIndiana State AGfiled 2024-08-18(17d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-04-colorado-state-university-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2024
- Raw hash
- a21dc27e4c567f6a93715ed199d2a3a27f3c2020c8f1a18236b42ae70bc5ebd6
Reporting entity
- Name
- The Colorado State University Systemnorm: the colorado state university system
- Domain
- colostate.edu
- Industry
- education
Victim entity
- Name
- Colorado State University - Pueblonorm: colorado state university pueblo
- Domain
- csupueblo.edu
- Industry
- education
Incident
- Discovered
- Aug 14, 2024
- Materiality determined
- —
- Notification sent
- Sep 4, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.