Cyber Incident Victim: Collegium Charter School
Date:
Jan 2023
Location:
United States of America
Summary
Collegium Charter School experienced an external system breach involving unauthorized access to sensitive personal information, including names and Social Security Numbers. The incident impacted one Maine resident, prompting the non-profit organization to provide affected individuals with 12 months of credit monitoring and identity theft recovery services. Written notifications were issued to inform those impacted by the hacking incident, which compromised personally identifiable data through a targeted security intrusion.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 12, 2023, Collegium Charter School, a non-profit educational institution based in Exton, Pennsylvania, experienced an external system breach resulting in unauthorized access to sensitive personal data. The breach was discovered the following day, January 13, 2023. The compromised information included the name of one individual in combination with their Social Security Number. This incident exclusively affected a single Maine resident, as confirmed in the breach notification submitted to the Maine Attorney General's Office by the school's legal representative, attorney Erica Lloyd of Lewis Brisbois Bisgaard & Smith LLP. The school classified the event as a hacking incident but did not disclose technical details regarding attack vectors, threat actor origins, or specific systems compromised.

Collegium Charter School initiated written notifications to the affected individual on May 24, 2023, approximately four months after breach discovery. The notification included an offer of 12 months of credit monitoring services alongside fully managed identity theft recovery assistance through an unspecified provider. No evidence suggested prior breaches affecting Maine residents within the preceding 12-month period. The delayed notification timeline between discovery (January 2023) and consumer notification (May 2023) was not explained in the submitted documentation. The school submitted a redacted copy of its general breach notification letter as part of its compliance with Maine's data breach reporting requirements.
