CSIDB logo
Incident

Kentucky Wesleyan College

Incident posture

Attack window
Sep 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
Kentucky Wesleyan College
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Kentucky Wesleyan College experienced a network security incident that temporarily disrupted system availability and potentially exposed sensitive personal information. The breach may have compromised names, Social Security numbers, birth dates, addresses, driver's license details, financial aid records, and other personally identifiable information including biometric data and tax identification numbers for over 31,000 individuals. While no direct evidence of data misuse was found, the institution implemented enhanced security measures following the incident and later provided affected parties with 24 months of credit monitoring and identity theft restoration services. Notification to impacted individuals occurred approximately six months after discovery, with the college establishing a dedicated call center for inquiries regarding the breach.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Kentucky Wesleyan College (KWC) experienced a network security incident that disrupted access to its files and systems, discovered on or around September 1, 2020. The college restored system availability following the incident and implemented additional security measures, though it did not publicly disclose technical details regarding the attack vector or intrusion methods. While KWC found no direct evidence of personal information misuse, it acknowledged that unauthorized actors potentially accessed sensitive data belonging to faculty, students, staff, and other affiliated individuals. The compromised information included names, Social Security numbers, birth dates, addresses, driver’s license numbers, and financial aid award details. In limited cases, additional personal identifying information (PII) such as taxpayer identification numbers, email or usernames with passwords or security questions, IRS-issued identity protection PINs, and biometric data like fingerprints may have been exposed.

KWC delayed public notification until March 20, 2021, approximately six months after detecting the incident. The college established a dedicated call center for inquiries and mailed formal notices to 31,796 potentially affected individuals. These postal notifications offered 24 months of complimentary credit monitoring and identity theft restoration services through Cyberscout, though this mitigation offering was omitted from KWC’s initial website announcement and FAQ documentation. The college did not elaborate on the reasons for the six-month gap between discovery and notification or provide specifics about containment procedures. The incident implicated financial aid data, which falls under Gramm-Leach-Bliley Act (GLBA) safeguards, though no regulatory enforcement actions were publicly confirmed in relation to the breach.

Sources

Sources available to members: 1 source.

CSIDB