HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Cambridge College
bd_e670e3cd233640d0 · schema v1 · pii pii-v1
Full breach record for Cambridge College →Cambridge College notified consumers of a cybersecurity incident occurring between Feb 20 and Mar 2, 2023. Unauthorized access led to the exfiltration of names, SSNs, financial account numbers, and medical information. Approximately 275 Rhode Island residents were impacted. The college engaged outside cybersecurity professionals and is offering 12 months of Equifax Credit Watch Gold.
Vermont clock✗ VT AG >45 bday24 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed275 affectedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-04-cambridge-college-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2023
- Raw hash
- a2339ac1f7286dfd5dfd8804318ea25cdcef667e450f79105a4df75b51a0efe3
Reporting entity
- Name
- Cambridge Collegenorm: cambridge college
Victim entity
- Name
- Cambridge Collegenorm: cambridge college
Incident
- Discovered
- Feb 20, 2023
- Materiality determined
- Aug 4, 2023
- Notification sent
- Aug 4, 2023
- Affected individuals
- 275
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(165 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.