University System of Georgia
Clustered 3 filings across 3 jurisdictions · filing window Jul 7, 2023 → Mar 28, 2024. View entity profile → Other incidents for this victim →
incident inc_e9d7ae18569540c6 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
CA OR
Leak Site · State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 28, 2023
When the intrusion reportedly occurred, per the linked filings
May 31, 2023
Reported by CALIFORNIA AG, OREGON AG filings
University System of Georgia
University System of Georgia (USG) experienced a data breach due to a vulnerability in Progress Software's MOVEit Secure File Transfer platform. The cybercriminal group CL0P exploited this vulnerability starting May 28, 2023, gaining unauthorized access to files. USG detected the breach on May 31, 2023, and immediately blocked the software. Affected data includes Social Security Numbers, dates of birth, bank account numbers, and tax documents. USG is offering complimentary Experian IdentityWorks and Identity Restoration services to affected individuals.
University System of Georgia reported a data breach to the Oregon Attorney General. The breach was reported on 2024-03-28. The breach occurred during 5/28/2023 - 5/31/2023. The breach was discovered on 5/31/2023. 700,000 individuals were affected. Notice was sent on 3/28/2024.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Affected (this filing): 700,000