Menu
Browse

Cyber Incident Victim: Kentucky Wesleyan College

Date:

Sep 2020

Location:

United States of America

Summary

Kentucky Wesleyan College experienced a network security incident that temporarily disrupted system availability and potentially exposed sensitive personal information. The breach may have compromised names, Social Security numbers, birth dates, addresses, driver's license details, financial aid records, and other personally identifiable information including biometric data and tax identification numbers for over 31,000 individuals. While no direct evidence of data misuse was found, the institution implemented enhanced security measures following the incident and later provided affected parties with 24 months of credit monitoring and identity theft restoration services. Notification to impacted individuals occurred approximately six months after discovery, with the college establishing a dedicated call center for inquiries regarding the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Kentucky Wesleyan College (KWC) experienced a network security incident that disrupted access to its files and systems, discovered on or around September 1, 2020. The college restored system availability following the incident and implemented additional security measures, though it did not publicly disclose technical details regarding the attack vector or intrusion methods. While KWC found no direct evidence of personal information misuse, it acknowledged that unauthorized actors potentially accessed sensitive data belonging to faculty, students, staff, and other affiliated individuals. The compromised information included names, Social Security numbers, birth dates, addresses, driver’s license numbers, and financial aid award details. In limited cases, additional personal identifying information (PII) such as taxpayer identification numbers, email or usernames with passwords or security questions, IRS-issued identity protection PINs, and biometric data like fingerprints may have been exposed.

Cyber Incident Image

KWC delayed public notification until March 20, 2021, approximately six months after detecting the incident. The college established a dedicated call center for inquiries and mailed formal notices to 31,796 potentially affected individuals. These postal notifications offered 24 months of complimentary credit monitoring and identity theft restoration services through Cyberscout, though this mitigation offering was omitted from KWC’s initial website announcement and FAQ documentation. The college did not elaborate on the reasons for the six-month gap between discovery and notification or provide specifics about containment procedures. The incident implicated financial aid data, which falls under Gramm-Leach-Bliley Act (GLBA) safeguards, though no regulatory enforcement actions were publicly confirmed in relation to the breach.

Sources
Sources available to members
1 source