CSIDB logo
Incident

Lewis & Clark College

Incident posture

Attack window
Mar 2023
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-26 06:00

Linked entities

Victim
Lewis & Clark College
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Lewis & Clark College experienced an IT security incident that disrupted systems and services across its campuses. Attackers published some of the college’s data on a dark web site, prompting an ongoing investigation by internal and external experts to determine what personal information was exposed. The college has stated that credit monitoring and identity restoration services are being provided at no cost to current and former students and employees while the review continues. Preliminary findings indicate that data from major systems such as payroll, student information and tuition payment platforms appear unaffected, though some passport information may have been included in the compromised material. The institution has also implemented additional security measures, including multi‑factor authentication for its virtual private network, as part of its response.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On March 3 2023 Lewis & Clark College experienced an IT security incident that negatively impacted systems and services across its campuses, prompting the institution’s IT team to work around the clock with external experts to restore operations and assess the situation. The attackers employed ransomware, a type of malicious software designed to block access to files and systems until a ransom is paid, and the group responsible is known for similar attacks against educational institutions. Following guidance from law enforcement and its forensic partners, the college decided not to pay the ransom and instead rebuilt its IT environment from regularly maintained backups. While restoration efforts proceeded, an external cybersecurity forensic firm was engaged to determine whether any protected or sensitive data had been compromised as a result of the breach. The cybercriminals later claimed to have published a limited amount of Lewis & Clark data on a dark‑web site, prompting the college to retrieve the material and begin a thorough review; by mid‑summer the external experts had examined roughly ninety percent of the files, a process that required significant manual analysis due to the complexity of the material.

The investigation revealed that the compromised data may include sensitive personal information, and the Office of Overseas and Off‑Campus Programs noted that at least some passport information collected for study‑abroad participants could be among the exposed records, although the full scope remained unknown. Some members of the college community reported fraudulent use of their personal information, including instances where tax returns were filed using their social security numbers, yet to date there has been no evidence that the data involved in the incident has been used for identity theft or financial fraud. Most IT systems have been fully restored since the initial outage, while the Pionet secure wifi network and the WebAdvisor password‑change function remained unavailable; restored or modified services included the Pionet‑Guest wifi network (which requires no login), the college’s websites, printing, the Virtual Private Network with multi‑factor authentication, Workday, Slate, Panopto, StarRez, on‑campus phone service, GMail and Google Workspace, Zoom, Maxient, dining, online facilities work orders, most classroom technology such as audio‑visual equipment, Handshake, Salesforce and Box, online trainings through GetInclusive, GivePulse, Colleague and Informer, WebAdvisor and Self Service, LC Files, Moodle, EMS, NuPark, Explorance Blue evaluations, GoAnywhere, ExLibris, the Secure Forms server, Courseleaf, CBORD, the Salesforce/Colleague integration, and centrally managed software licenses such as ESRI ArcGIS, SPSS, and Mathematica.

In response to the incident the college made free credit monitoring available to current students and employees at its expense, with enrollment accessible through a short request form that required an lclark.edu Google account and provided an activation code upon submission. Individuals who suspected fraudulent use of their information were directed to Experian credit monitoring and associated identity‑restoration services, which include twelve months of support from the date of engagement. The institution advised anyone who had not yet changed their password to do so, specifying that the new password must be between nine and nineteen characters, contain at least four letters, include both uppercase and lowercase letters, incorporate a number, and differ from the previous password, with changes possible at the IT Service Desk in Watzek Library or the Law School Help Desk. Multi‑factor authentication was implemented for the GlobalProtect VPN, and Google Plus licenses were deployed to all staff and faculty to enhance security. The IT Governance Council produced a report documenting the college’s ongoing cybersecurity efforts, which community members could access using their LC credentials. Lewis & Clark committed to issuing formal written notification to any individual whose protected information is confirmed to have been compromised, in accordance with applicable state and federal laws, once the investigation concludes. The college also shared information about placing fraud alerts or security freezes on credit files, obtaining free annual credit reports, contacting law enforcement, and filing complaints with the Federal Trade Commission, and it encouraged the community to report suspicious messages to [email protected].

Sources

Sources available to members: 1 source.

CSIDB