Colorado State University - Pueblo
bd_f5d8040d4a3cf6da · schema v1 · pii pii-v1
Full breach record for Colorado State University - Pueblo →Colorado State University – Pueblo reported a phishing incident on August 14, 2024, where an employee was targeted by a social engineering attack impersonating the university controller. The employee sent an unprotected Excel spreadsheet containing student information (names, SSNs, DOBs, etc.) to an unauthorized third party. The breach was discovered on August 15, 2024. A total of 11,079 individuals were affected, including 4 New Hampshire residents. The university notified affected individuals electronically on August 18, 2024, and implemented additional employee cybersecurity training.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_61c4d57e333de213Maine State AGfiled 2024-09-05Candidate
- bd_e08271f0e5d8cffbVermont State AGfiled 2024-09-04(1d gap)Verified
- bd_4cbc52f0b9c4f0faIndiana State AGfiled 2024-08-18(18d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/board-governors-colorado-state-university-pueblo-20240905.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2024
- Raw hash
- 7f2e9aa68ae316f2a8a1a3302599f19fa9e47deb065995cf0c66a99d0492fb07
Reporting entity
- Name
- The Board of Governors of the Colorado State University Systemnorm: the board of governors of the colorado state university system
- Domain
- csusystem.edu
- Industry
- education
Victim entity
- Name
- Colorado State University - Pueblonorm: colorado state university pueblo
- Domain
- csupueblo.edu
- Industry
- education
Incident
- Discovered
- Aug 15, 2024
- Materiality determined
- —
- Notification sent
- Aug 18, 2024
- Affected individuals
- 11,079
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.