Cyber Incident Victim: College of DuPage
Date:
Mar 2020
Location:
United States of America
Summary
A cybersecurity incident at the College of DuPage compromised personal and tax information, including 2018 W-2 forms, belonging to 1,755 current and former employees. While officials assessed a low likelihood of fraudulent use, they notified affected individuals and provided complimentary credit monitoring and identity protection services. The institution implemented additional procedural safeguards to prevent future breaches, though the investigation did not conclusively determine the incident's origin, timing, or discovery. The breach occurred amid organizational changes related to pandemic response efforts, with leadership expressing regret for the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The College of DuPage in Glen Ellyn, Illinois, confirmed a data breach on March 16, 2020, compromising personal and tax information of 1,755 current and former employees. Exposed data included 2018 W-2 tax forms containing sensitive employee details. College President Brian Caputo publicly acknowledged the incident but did not disclose when the breach occurred, when it was discovered, or the specific method of data exposure. While Caputo stated the likelihood of criminals obtaining or misusing the information was low, the college initiated breach notifications to affected individuals out of caution. The breach coincided with the institution's transition to alternative instruction plans due to the emerging COVID-19 pandemic, though no coronavirus cases had been reported among campus personnel at the time of disclosure.

In response, the college offered complimentary credit monitoring and identity protection services to all impacted individuals. Caputo emphasized the institution's commitment to protecting private information by implementing additional procedural safeguards to prevent future breaches. An internal investigation failed to produce conclusive findings regarding the breach's origin or methodology. The college issued a formal apology through Caputo, who expressed regret for the incident and any resulting concerns. No technical details about affected systems, containment measures, or attacker actions were released publicly. The incident remained under investigation with no further updates disclosed in the immediate aftermath of the announcement.
