CSIDB logo
Incident

College of DuPage

Incident posture

Attack window
Mar 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
College of DuPage
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident at the College of DuPage compromised personal and tax information, including 2018 W-2 forms, belonging to 1,755 current and former employees. While officials assessed a low likelihood of fraudulent use, they notified affected individuals and provided complimentary credit monitoring and identity protection services. The institution implemented additional procedural safeguards to prevent future breaches, though the investigation did not conclusively determine the incident's origin, timing, or discovery. The breach occurred amid organizational changes related to pandemic response efforts, with leadership expressing regret for the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The College of DuPage in Glen Ellyn, Illinois, confirmed a data breach on March 16, 2020, compromising personal and tax information of 1,755 current and former employees. Exposed data included 2018 W-2 tax forms containing sensitive employee details. College President Brian Caputo publicly acknowledged the incident but did not disclose when the breach occurred, when it was discovered, or the specific method of data exposure. While Caputo stated the likelihood of criminals obtaining or misusing the information was low, the college initiated breach notifications to affected individuals out of caution. The breach coincided with the institution's transition to alternative instruction plans due to the emerging COVID-19 pandemic, though no coronavirus cases had been reported among campus personnel at the time of disclosure.

In response, the college offered complimentary credit monitoring and identity protection services to all impacted individuals. Caputo emphasized the institution's commitment to protecting private information by implementing additional procedural safeguards to prevent future breaches. An internal investigation failed to produce conclusive findings regarding the breach's origin or methodology. The college issued a formal apology through Caputo, who expressed regret for the incident and any resulting concerns. No technical details about affected systems, containment measures, or attacker actions were released publicly. The incident remained under investigation with no further updates disclosed in the immediate aftermath of the announcement.

Sources

Sources available to members: 1 source.

CSIDB