Washington State University
ent_67d2f051fb21028ee1da7cc8
Disclosures
10
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,118,135
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Washington State University
- Normalized
- washington state university— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- wsu.edu
Disclosure history (10)newest first
- Washington State AGas victim2024-07-18
Washington State University (WSU) Cougar Health Services Pharmacy issued substitute notice for a third-party breach by Change Healthcare. Ransomware deployed Feb 21, 2024; data exfiltrated Feb 17-20. Affected data includes PHI, PII, and financial info. No specific patient count provided by vendor. WSU disabled connection and is monitoring vendor response.
- Washington State AGas victim2020-08-17
Washington State University Foundation notified of ransomware attack on third-party vendor Blackbaud, Inc. Incident occurred Feb 7 - May 20, 2020; discovered July 16, 2020. Exposed names, DOBs, and relationship info for ~334,219 Washington residents. No financial data or SSNs involved. Vendor contained threat and engaged forensics/law enforcement.
- New Hampshire State AGas victim2017-06-22
Washington State University filed a supplemental notification with the New Hampshire Attorney General regarding a security incident affecting 521 NH residents. The investigation is complete. The university mailed notices and offered one year of credit monitoring via Experian.
- South Carolina State AGas victim2017-06-12
Washington State University notified individuals that a locked safe containing a hard drive with backed-up files from the Social & Economic Sciences Research Center was stolen. The drive contained unencrypted personal information (name, address) of survey participants and minors. The university notified law enforcement, engaged forensic investigators, and offered credit monitoring services.
- California State AGas victim2017-06-09
Washington State University reported the theft of a locked safe containing a hard drive on April 21, 2017. The drive contained unencrypted personal information (names, addresses) of survey participants, including minors, from the Social & Economic Sciences Research Center. The university notified law enforcement, retained forensic investigators, and offered credit monitoring to affected individuals. No evidence of data misuse was found.
- Massachusetts State AGas victim2017-06-09
Washington State University reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-06-09. 3,399 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-06-09
Washington State University notified the NH AG of a stolen hard drive containing unencrypted PII (names, addresses, SSNs) of 469 NH residents. Discovered April 21, 2017. Notifications sent June 9, 2017. Credit monitoring offered.
- Montana State AGas victim2017-06-09
Washington State University notified individuals that a locked safe containing a hard drive with backed-up files from the Social & Economic Sciences Research Center was stolen on or before April 21, 2017. The drive contained unencrypted personal information including names and addresses of survey participants and minors. The University notified law enforcement, engaged forensic investigators, and offered one year of credit monitoring/identity protection services.
- Oregon State AGas victim2017-06-09
Washington State University reported a data breach to the Oregon Attorney General. The breach was reported on 2017-06-09. The breach occurred during 4/21/2017 - 4/21/2017. The breach was discovered on 4/26/2017. 1,118,135 individuals were affected. Notice was sent on 6/9/2017.
- Washington State AGas victim2017-06-08
Washington State University reported the theft of a locked safe containing an unencrypted hard drive with backed-up files from the Social & Economic Sciences Research Center. The drive held PII (names, addresses, SSNs) for ~1.1M individuals and PHI for ~666. Discovered April 21, 2017. Notifications sent June 9, 2017. Credit monitoring offered.