HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
The Trustees of the University of Pennsylvania
bd_ebfa6b15607e7cd7 · schema v1 · pii pii-v1
Full breach record for The Trustees of the University of Pennsylvania →University of Pennsylvania reported a third-party vendor breach on 10/29/2023, discovered 03/22/2024, affecting 388 individuals (1 in Maine). Compromised data included names and Social Security Numbers. The university notified affected individuals in writing on 04/09/2024 and provided 24 months of credit monitoring via Experian.
Maine clockDiscovered Mar 22, 2024 → Filed with AG May 24, 202463d ⏱ ME AG >30d9 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_711e07d2b3e1e4c7Indiana State AGfiled 2024-04-09(45d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c10c2fd9-4359-422c-99f6-9c57ff8a5a54.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2024
- Raw hash
- 35082c505cbffcd3ae52b04a8b0d559e49068809c78e2361d3bd8987cda48d14
Reporting entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
- Domain
- upenn.edu
- Industry
- Education
Victim entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
- Domain
- upenn.edu
- Industry
- Education
Incident
- Discovered
- Mar 22, 2024
- Materiality determined
- —
- Notification sent
- Apr 9, 2024
- Affected individuals
- 388
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- ME AG >30d · 63d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 22, 2024→ Filed with AG: May 24, 202463d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.