Cyber Incident Victim: St. Joseph's College of Maine
Date:
Dec 2023
Location:
United States of America
Summary
St. Joseph's College of Maine experienced an external system breach compromising personal identifiers, including names, for over 126,000 individuals—approximately 23,000 of whom were Maine residents. The hacking incident was discovered over a year after it occurred, prompting written notifications to affected parties and offers of 12 months of credit monitoring and identity theft protection through Experian.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On December 15, 2023, St. Joseph’s College of Maine experienced an external system breach involving unauthorized hacking activity. The incident remained undetected for over fourteen months until its discovery on February 20, 2025. The breach compromised personal identifiers—including names—for 126,580 individuals, with 23,203 affected parties identified as Maine residents. The Standish-based educational institution, located at 278 Whites Bridge Road, reported the incident through legal representative Heather Shumaker of McDonald Hopkins LLC. The scale of the breach triggered mandatory notifications to consumer reporting agencies under Maine law due to the number of affected residents exceeding 1,000. No evidence suggested prior breach notifications from the college within the preceding twelve-month period. The delayed discovery timeline indicates prolonged unauthorized access to systems before detection.

In response, St. Joseph’s College initiated written notifications to all affected individuals on March 21, 2025, with sample correspondence filed in Maine’s official breach documentation. The institution contracted with Experian to provide twelve months of credit monitoring and identity theft protection services to impacted parties. The breach disclosure did not specify whether forensic investigations identified specific threat actors or detailed the exact systems compromised beyond confirming external system infiltration. The legal submission confirmed the absence of additional breach mitigation details beyond the notification timeline and protection services. The college’s attorney provided contact information for regulatory inquiries but did not disclose remediation costs, operational disruptions, or technical containment measures undertaken post-discovery.
