The Chronicle
ent_67441d1de9adab91ccb0997a
Disclosures
2
State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Chronicle
- Normalized
- the chronicle— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- thechronicle.com
Disclosure history (2)newest first
- 🐻California State AGas victim2020-07-10
The Chronicle of Higher Education, Inc. disclosed a data breach affecting online accounts on chronicle.com, philanthropy.com, and chroniclevitae.com. Unauthorized parties exploited a server vulnerability to access account information, including names, emails, usernames, and passwords (some in plain text). The company reset passwords, replaced the affected server, and notified law enforcement.
- 🐻California State AGas victim2020-05-13
The Chronicle of Higher Education, Inc. disclosed that unauthorized parties exploited a server vulnerability to obtain administrative credentials and accessed a database containing hashed and salted passwords for online accounts on February 17, 2020. The incident was discovered on May 10, 2020, after an internal alert. The company took the server offline, engaged forensic investigators, and notified law enforcement. Affected users were prompted to change passwords, and the company implemented stronger hashing technology and replaced the affected server.