Confirmed breach. Intrusion May 29, 2023–May 30, 2023, discovered Jul 10, 2023 — the first regulatory filing landed 37 days later. 19,344 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedcl0p
Affected (total reported)
19,344
Data types
—
Jurisdictions
2
MT NH
Linked filings
2
all State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
May 29, 2023
When the intrusion reportedly occurred, per the linked filings
The Board of Governors of the Colorado State University System reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-16. The breach occurred from 5/29/2023 to 5/30/2023. 92 Montana residents were affected.
Affected (this filing): 92
⛰️New Hampshire State AGMost recentlinked via multistate filing link · 100%
The Board of Governors of the Colorado State University System (CSU) notified the New Hampshire Attorney General of a security event involving third-party vendors Pension Benefits Information, LLC (PBI) and the National Student Clearinghouse (NSC). The Clop threat actor exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data. While CSU's own systems were not directly impacted, 19,344 individuals whose data was held by vendors on behalf of CSU were affected, including 37 New Hampshire residents. CSU issued community notices and vendors provided two years of complimentary credit monitoring through Kroll.
Affected (this filing): 19,344
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.