Kent State University notified Vermont AG of a third-party data breach involving vendor Keffer Development Services, LLC. An unauthorized party used brute-force methods to access administrative credentials for the Athletic Trainer Services (ATS) platform, exposing student-athlete PII including names, DOBs, SSNs, and health data. Kent State convened an IR team, reset passwords, and mandated stricter controls for Keffer. Complimentary credit monitoring was offered. No Kent State systems were directly compromised.