Clustered 3 filings across 3 jurisdictions · filing window Aug 12, 2023 → Aug 17, 2023. View entity profile → Other incidents for this victim →
incident inc_1e5891e708fc4206 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME OR
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 29, 2023 → May 30, 2023
When the intrusion reportedly occurred, per the linked filings
May 31, 2023
Reported by CALIFORNIA AG filing
Jul 10, 2023
Reported by OREGON AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The Colorado State University System reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-12. The breach occurred during 5/29/2023 - 5/30/2023. The breach was discovered on 7/10/2023. Notice was sent on 7/12/2023.
The Colorado State University System experienced an external system breach (hacking) on May 29, 2023, discovered on July 10, 2023. The incident compromised the names and Social Security Numbers of 19,344 individuals, including 29 Maine residents. The university provided written notification on July 12, 2023, and offered 24 months of credit monitoring and ID restoration services through Kroll.
Affected (this filing): 19,344
Pension Benefit Information, LLC (PBI) notified the California AG of a data event involving its MOVEit Transfer software. An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer to access PBI's server on May 29-30, 2023, and downloaded data. PBI discovered the incident on May 31, 2023, when Progress disclosed the vulnerability. Affected data includes names and other data elements. PBI patched servers, investigated the scope, and is offering credit monitoring via Kroll. The incident is contained.