Bennett College
Incident posture
Linked entities
- Victim
- Bennett College
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Bennett College experienced a data breach that exposed personal information of at least 30,065 individuals, including at least 10,875 residents of North Carolina. The compromised data may have included names, Social Security numbers, driver’s license or state identification numbers, dates of birth, alien registration numbers, financial account details, taxpayer identification numbers, passport numbers, digital signatures, medical information and health insurance information. After discovering the incident, the college contacted law enforcement, hired third‑party forensic experts, secured its systems and began offering credit monitoring and identity protection services to those affected. Ransomware monitoring services later noted that the institution’s domain appeared on a leak site associated with an extortion group.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Bennett College experienced a cyber attack that occurred between October 27 and November 15, during which certain information stored on its network was subject to unauthorized access for a limited period of time. The college issued a news release after discovering the breach and subsequently filed a data breach notification with the North Carolina Attorney General’s Office, which was received on a Friday. According to that filing, the breach affected at least 30,065 individuals, of whom at least 10,875 were residents of North Carolina. The college did not specify in the release whether the affected individuals were students, faculty, staff or other affiliates.
Following its investigation, Bennett College stated that the compromised information likely varied by individual but could include name, Social Security number, driver’s license or state identification number, date of birth, U.S. alien registration number, financial account information, taxpayer identification number, passport number, digital signature, medical information and/or health insurance information. Independent ransomware monitoring services DeXpose and Galaxy Warden reported that the domain Bennett.edu appeared on an Incransom leak site on December 6. The college noted that upon discovery it immediately contacted law enforcement and engaged third‑party computer forensic specialists to determine the nature and scope of the incident.
To address the breach, Bennett College said it took immediate steps to secure its systems and enhance the security of its network. The institution is providing potentially affected individuals with access to credit monitoring and identity protection services, and has made a toll‑free number (866‑899‑7220) available from 8 a.m. to 8 p.m. for assistance. The article also noted that, since the start of 2025, other organizations in the Triad region—including Preferred Parking Service, Atrium Health, Belk's, Food Lion, the Greensboro immigration law firm of Chapman & Roberts PA, Krispy Kreme Inc. and Triad Radiology Associates—have experienced data breaches.
Sources
Sources available to members: 1 source.