Aspen Education Group, Inc.
ent_789b76fa8611a04f4d87a602
Disclosures
10
State AG · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
57,763
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Aspen Education Group, Inc.
- Normalized
- aspen education— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- ACADIA HEALTHCARE COMPANY, INC.— per SEC Exhibit 21 filing
Disclosure history (10)newest first
- South Carolina State AGas victim2021-05-11
Aspen Education Group, Inc. notified South Carolina residents of a December 13, 2020 incident where an unauthorized person gained access to its network and deployed malware. The incident may have exposed names, addresses, and dates of birth. The company engaged forensic investigators and offered one year of Experian Identity Works. No misuse was indicated.
- New Hampshire State AGas victim2021-05-10
Aspen Education Group, Inc. notified the NH Attorney General of a security incident where an unauthorized person gained access to the network on December 13, 2020, deployed malware, and exfiltrated documents. The breach affected 377 New Hampshire residents, exposing names, dates of birth, and Social Security numbers. The company engaged forensic investigators, secured the network, and offered one year of credit monitoring.
- Maine State AGas victim2021-05-10
Aspen Education Group, Inc. experienced an external system breach (hacking) on December 13, 2020, which was discovered on March 11, 2021. The breach affected 279 Maine residents, compromising their names and Social Security numbers. The company provided one year of credit monitoring and identity theft protection services through Experian.
- Oregon State AGas victim2021-05-10
Aspen Education Group, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-05-10. The breach occurred during 12/13/2020 - 12/13/2020. The breach was discovered on 3/11/2021. 57,763 individuals were affected. Notice was sent on 5/10/2021.
- Washington State AGas victim2021-05-10
Aspen Education Group, Inc. notified Washington AG of a Dec 13, 2020 cyberattack where malware was deployed and documents containing PII (names, DOB, SSN, health info) of 1,958 WA residents were accessed. Notifications mailed May 10, 2021, offering 1-year credit monitoring.
- Montana State AGas victim2021-05-10
Aspen Education Group, Inc. notified Montana residents of a December 13, 2020 incident where an unauthorized person gained access to its network and deployed malware. The incident involved the acquisition of documents containing names, addresses, and dates of birth. The company engaged forensic investigators and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
- Massachusetts State AGas victim2021-05-10
Aspen Education Group, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-10. 1,684 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-05-10
Aspen Education Group, Inc. notified the California Attorney General of a data breach occurring on December 13, 2020. An unauthorized actor gained access to the network, deployed malware, and exfiltrated documents containing names, addresses, and dates of birth of individuals who had inquired about programs. The company engaged forensic investigators, secured the network, and offered one year of identity monitoring services to affected individuals.
- Indiana State AGas victim2021-05-10
Aspen Education Group, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-08-23 and was reported on 2021-05-10. 682 Indiana residents were affected. 57,763 individuals affected in total.
- Illinois State AGas victim2021-01-01
ASPEN EDUCATION GROUP, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-164). The register records the breach as discovered on December 13, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.