HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEDUCATIONMediumContained
BYU-Pathway
bd_f3bcc3c9c7034487 · schema v1 · pii pii-v1
Full breach record for BYU-Pathway →BYU-Pathway Worldwide detected unauthorized network access on June 17, 2025, involving a compromised vendor account. The incident affected student personal data, including names, SSNs, contact info, and educational records. Access was removed on June 24, 2025. The organization engaged forensic experts, notified law enforcement, and is offering credit monitoring to affected students.
California clockDiscovered Jun 17, 2025 → Notified Jul 14, 202527d ✓ CA 60-day OK4 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_6da270133e0e6007Maine State AGfiled 2025-07-18Verified
- bd_db8c1de2569f654dTexas State AGfiled 2025-07-22(4d gap)Verified
- bd_1fe33b05c99617d1Washington State AGfiled 2025-07-14(4d gap)Candidate
- bd_25f637a3dd569afeMontana State AGfiled 2025-07-14(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_3269f8329e9ed768Indiana State AGfiled 2025-07-14(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605664
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 18, 2025
- Raw hash
- 8803bc25294e0e4f86f084cbb872daa06a5122ccc75a85d2d015155321e38e16
Reporting entity
- Name
- BYU-Pathwaynorm: byu pathway
- Domain
- byupathway.edu
Victim entity
- Name
- BYU-Pathwaynorm: byu pathway
- Domain
- byupathway.edu
Incident
- Discovered
- Jun 17, 2025
- Materiality determined
- —
- Notification sent
- Jul 14, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEDUCATION
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement authorities in the United StatesNotified state attorneys general, credit reporting agencies, or other regulatory authorities where legally required
- Third party
- via Unknown vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 27d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 17, 2025→ Notified: Jul 14, 202527d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.