California State University East Bay
ent_5a6e01bbd474c5e4b3c10670
Disclosures
6
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
6
as filed · State AG MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California State University East Bay
- Normalized
- california state university east bay— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- California State AGas victim2018-10-12
California State University East Bay disclosed that an unknown third-party exploited a vulnerability in a university web application to access and exfiltrate personal information, including names, addresses, and Social Security numbers. The unauthorized access occurred between March 27, 2017, and September 2, 2018, and was discovered on September 17, 2018. The university removed the compromised application, mitigated vulnerabilities, and offered 12 months of credit monitoring to affected individuals.
- New Hampshire State AGas victim2018-10-08
California State University, East Bay notified the NH AG of a breach affecting 1 NH resident. Unauthorized access occurred between March 27, 2017, and Sept 2, 2018, via a web app exploit. Data exposed: names, addresses, SSNs. Notification sent Oct 5, 2018. Remediation: app removed, vulns mitigated, credit monitoring offered.
- Massachusetts State AGas victim2018-10-05
California State University East Bay reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-10-05. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas reporting2018-10-05
Rebound Orthopedics & Neurosurgery notified individuals of a data breach where an unknown individual accessed an employee's email account on May 22, 2018. Personal information including names, SSNs, DOBs, driver's license numbers, and financial account data were potentially disclosed. The company engaged forensic investigators and offered one year of identity monitoring via Kroll.
- California State AGas victim2014-09-05
California State University, East Bay disclosed that an unknown third-party gained unauthorized access to a university web server on August 23, 2013, using an overseas IP address and a software tool. The incident was discovered on August 11, 2014. The attacker copied a data file containing full names, addresses, Social Security numbers, and dates of birth for affected individuals. No financial, banking, academic, or medical information was included. The university removed malicious files, mitigated vulnerabilities, and offered 12 months of credit monitoring.
- New Hampshire State AGas victim2014-09-05
California State University, East Bay notified the NH AG of a breach affecting 2 NH residents. Unauthorized access occurred on Aug 23, 2013, discovered Aug 11, 2014. Attackers used an overseas IP and software tool to access a web server storing employment records. Exfiltrated data included names, addresses, and SSNs. CSUEB removed malicious files, mitigated vulnerabilities, and offered 1-year credit monitoring.