Grinnell College
ent_1e97dc6fd198f0f3286dd92c
Disclosures
11
State AG · 7 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
2,465
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Grinnell College
- Normalized
- grinnell college— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- New Hampshire State AGas victim2023-10-02
Grinnell College notified the NH AG of an error on May 7, 2023, where payroll files containing employee PII were inadvertently saved in a shared folder accessible to authenticated users. Files were moved on March 13, 2023. 11 NH residents affected. No evidence of misuse. Remediation included restricting access, engaging forensic firm, and offering credit monitoring.
- Montana State AGas victim2023-09-29
Grinnell College disclosed that on March 13, 2023, an employee inadvertently moved payroll files to a shared internal folder accessible by any user with valid credentials. The files were accessed by a limited number of users between May 4 and May 7, 2023. The files contained names, addresses, SSNs, salary, and tax info. No external access or misuse was detected. The incident was remediated on May 7, 2023, and credit monitoring was offered.
- Massachusetts State AGas victim2023-09-29
Grinnell College reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-29. 25 Massachusetts residents were affected. The report records the breach type as electronic.
- Vermont State AGas victim2023-09-29
Grinnell College disclosed that an employee inadvertently moved payroll files to a shared internal folder accessible by any user with credentials. The files contained names, addresses, SSNs, and salary/tax info. No external access or misuse was detected. The incident was contained on the day of discovery (May 7, 2023), and affected individuals were offered credit monitoring.
- Maine State AGas victim2023-09-29
Grinnell College reported an inadvertent disclosure of personal information, including Social Security Numbers, affecting 2,319 individuals (6 in Maine). The breach occurred on March 13, 2023, and was discovered on May 7, 2023. Notification was sent on September 29, 2023, offering 12 months of Experian IdentityWorks.
- Indiana State AGas victim2023-09-29
Grinnell College reported a data breach to the Indiana Attorney General. The breach occurred on 2023-03-13 and was reported on 2023-09-29. 12 Indiana residents were affected. 2,319 individuals affected in total.
- Massachusetts State AGas victim2021-01-12
Grinnell College reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-12. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2021-01-05
Grinnell College reported a ransomware incident involving third-party provider Blackbaud affecting 2,465 Washington residents. Data accessed between Feb 7 and May 20, 2020, included names and DOBs. Ransom was paid for data destruction. Notification sent Jan 5, 2021.
- Massachusetts State AGas victim2019-05-10
Grinnell College reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-05-10. 96 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2019-03-29
Grinnell College notified the NH AG of an incident where an unauthorized individual accessed admission-related systems on March 7, 2019. Discovered March 9, 2019, the breach affected 13 NH residents, exposing names, addresses, DOBs, and SSNs. Grinnell engaged forensic experts and law enforcement, offering 2 years of credit monitoring to victims.
- Montana State AGas victim2019-03-25
Grinnell College issued a supplemental notification to Montana residents regarding a March 7, 2019, unauthorized access to its admission-related information system. The incident exposed names, addresses, dates of birth, and Social Security numbers. The college engaged forensic professionals and law enforcement, and offered two years of credit monitoring.