Nelnet Campus Commerce
ent_2d6e8da5f65dc6394d18171b
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,145
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Nelnet Campus Commerce
- Normalized
- nelnet campus commerce— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- New Hampshire State AGas victim2022-02-25
Nelnet Campus Commerce notified the NH AG of a data event affecting 15 NH residents. Unauthorized access to the TMS platform occurred Jan 17-19, 2022. Data exposed: names, SSNs, addresses, student IDs. Nelnet disabled credentials, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring.
- Massachusetts State AGas victim2022-02-22
Nelnet Campus Commerce reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-02-22. 272 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-02-18
Nelnet Campus Commerce experienced an external system breach between January 17, 2022, and January 19, 2022, discovered on the final day of the intrusion. The breach resulted in the compromise of names and Social Security numbers for affected individuals, including 12 residents of Maine. The company offered 24 months of complimentary identity theft protection services through Experian to those impacted.
- Indiana State AGas victim2022-02-18
Nelnet Campus Commerce reported a data breach to the Indiana Attorney General. The breach occurred on 2022-01-17 and was reported on 2022-02-18. 7 Indiana residents were affected. 3,145 individuals affected in total.
- California State AGas victim2022-02-18
Nelnet Campus Commerce disclosed that an unauthorized individual accessed a third-party reporting application maintaining student and authorized payer data for university clients, including Berklee College of Music. The incident occurred between January 17 and January 19, 2022, and was discovered on January 19, 2022. Affected data included names and other basic identity information; payment information was not compromised. Nelnet disabled credentials, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring.