HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICLowContained
Webber International University
bd_fe29a370d696d871 · schema v1 · pii pii-v1
Full breach record for Webber International University →Webber International University notified consumers of a data breach occurring around February 28, 2024. An unauthorized party copied files from the university's network. The data involved names and potentially other personal information. The university engaged third-party specialists, notified law enforcement and regulators, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by ransomhouse about this victim predates this filing by 125 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3761a43a780cd8d1Leak Siteransomhousefiled 2024-01-20(125d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_5be8d84ae0c3f756Montana State AGfiled 2024-05-24Verified by operator
- bd_deb8f9a25d981654Maine State AGfiled 2024-05-24Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-24-webber-international-university-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2024
- Raw hash
- 4cb54ad30a1d5ec2eb2bf872e3f94f9effd0a82749ef56649b634dacc19626db
Reporting entity
- Name
- Webber International Universitynorm: webber international university
- Domain
- webber.edu
Victim entity
- Name
- Webber International Universitynorm: webber international university
- Domain
- webber.edu
Incident
- Discovered
- Feb 28, 2024
- Materiality determined
- —
- Notification sent
- May 24, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified relevant state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.