The Colorado State University System
ent_3fe84fc8811e69b35ee75583
Disclosures
7
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
19,344
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Colorado State University System
- Normalized
- the colorado state university system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- colostate.edu
Disclosure history (7)newest first
- Maine State AGas reporting2024-09-05
Colorado State University - Pueblo reported a social engineering attack on August 14, 2024, targeting employees to access an unprotected Excel spreadsheet containing student names, IDs, and billing balances. Approximately 11,079 individuals were affected, including 2 Maine residents. Notification was sent electronically on August 18, 2024.
- Massachusetts State AGas victim2023-08-17
The Colorado State University System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-17. 144 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-08-16
The Colorado State University System experienced an external system breach (hacking) on May 29, 2023, discovered on July 10, 2023. The incident compromised the names and Social Security Numbers of 19,344 individuals, including 29 Maine residents. The university provided written notification on July 12, 2023, and offered 24 months of credit monitoring and ID restoration services through Kroll.
- Oregon State AGas victim2023-08-12
The Colorado State University System reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-12. The breach occurred during 5/29/2023 - 5/30/2023. The breach was discovered on 7/10/2023. Notice was sent on 7/12/2023.
- Washington State AGas victim2023-07-16
Pension Benefit Information, LLC (PBI) disclosed a data breach involving the MOVEit Transfer software vulnerability exploited by an unauthorized third party on May 29-30, 2023. The attacker downloaded PII, including names and government IDs, from PBI servers. PBI patched systems, investigated, and offered 24 months of credit monitoring. The incident is linked to the global Progress Software MOVEit vulnerability.
- Massachusetts State AGas victim2023-07-13
The Colorado State University System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-13. The report records the breach type as electronic.
- Indiana State AGas victim2023-07-12
The Colorado State University System reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-29 and was reported on 2023-07-12. 68 Indiana residents were affected. 19,344 individuals affected in total.
Supply-chain cascadesreviewed and confirmed
- The Colorado State University System’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).