DisclosureLens
Social EngineeringEducationEducationPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHighContained

North Carolina State University

bd_f3b26edffd203516 · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 3, 2016

Filed

Jul 8, 2016

To disclose

5 weeks

Affected · nationwide

36,40335 in this filing

Linked

3 filings

Confidence

67%
Full breach record for North Carolina State University3 incidents on file

North Carolina State University notified New Hampshire AG of a phishing attack on June 3, 2016 that compromised an employee email account. The breach exposed names, SSNs, and 2013 mailing addresses of approximately 36,403 students. 35 New Hampshire residents were affected. NC State engaged forensics, reset credentials, implemented 2-Step Verification, and provided one year of credit monitoring.

Incident timeline

discovery → filing · 5 weeks / 35 days

Jun 3, 2016

Discovered

Jul 8, 2016

Filed

vs. sector median

4 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGJul 8 · first
New Hampshire State AGJul 8 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.