The Board of Governors of the Colorado State University System
ent_c8e143679ef02c91b636930e
Disclosures
4
State AG · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
19,344
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Board of Governors of the Colorado State University System
- Normalized
- the board of governors of the colorado state university system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- csusystem.edu
Disclosure history (4)newest first
- Montana State AGas reporting2024-09-05
Colorado State University – Pueblo notified affected individuals of a cybersecurity incident on August 14, 2024. Employees were targeted by a social engineering attack, resulting in unauthorized access to an unprotected Excel spreadsheet containing student names, ID numbers, and billing balances. No university systems were breached. The incident was limited in scope.
- New Hampshire State AGas reporting2024-09-05
Colorado State University – Pueblo reported a phishing incident on August 14, 2024, where an employee was targeted by a social engineering attack impersonating the university controller. The employee sent an unprotected Excel spreadsheet containing student information (names, SSNs, DOBs, etc.) to an unauthorized third party. The breach was discovered on August 15, 2024. A total of 11,079 individuals were affected, including 4 New Hampshire residents. The university notified affected individuals electronically on August 18, 2024, and implemented additional employee cybersecurity training.
- New Hampshire State AGas victim2023-08-17
The Board of Governors of the Colorado State University System (CSU) notified the New Hampshire Attorney General of a security event involving third-party vendors Pension Benefits Information, LLC (PBI) and the National Student Clearinghouse (NSC). The Clop threat actor exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data. While CSU's own systems were not directly impacted, 19,344 individuals whose data was held by vendors on behalf of CSU were affected, including 37 New Hampshire residents. CSU issued community notices and vendors provided two years of complimentary credit monitoring through Kroll.
- Montana State AGas victim2023-08-16
The Colorado State University System (CSU) notified Montana regulators of a security event involving third-party vendors Pension Benefits Information (PBI) and the National Student Clearinghouse (NSC). The Russian threat actor Clop exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data including names and Social Security numbers. While CSU's own systems were not directly affected, 19,344 individuals whose data was held by vendors on behalf of CSU were impacted, including 92 Montana residents. CSU and vendors are providing two years of credit monitoring.