Menu
Browse

Cyber Incident Victim: Treasure Valley Community College

Date:

Jun 2019

Location:

United States of America

Summary

Treasure Valley Community College experienced a data security incident involving unauthorized access to an employee email account over a six-month period, potentially exposing personal information of community members including student ID numbers, Social Security numbers, and dates of birth. The college discovered the breach months after the potential compromise and notified affected individuals, though some could not be reached due to incomplete contact information. While no misuse of information was identified, the institution offered complimentary credit monitoring services and established a dedicated call center to assist impacted parties. The college implemented measures to prevent future occurrences following the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Treasure Valley Community College (TVCC) discovered a data security incident involving unauthorized access to an employee email account, which was identified on August 25, 2020. The breach potentially exposed personal information of certain TVCC community members, with the unauthorized access occurring between June and December 2019—a timeframe spanning approximately six months. The compromised data included student identification numbers, Social Security numbers, and dates of birth. TVCC initiated an investigation upon discovery but did not identify the perpetrator or determine the exact scope of data exfiltration beyond the confirmed exposure within the email account. The college acknowledged that the delay between the breach period and its detection hindered immediate containment efforts.

Cyber Incident Image

TVCC began notifying affected individuals following its investigation, though it lacked sufficient contact information for a subset of individuals whose student ID numbers and dates of birth were involved. The institution offered complimentary credit monitoring services to all impacted parties and established a toll-free call center operational on weekdays from 8:00 a.m. to 8:00 p.m. Central Time to assist with enrollment and inquiries. While TVCC stated no evidence of misuse of the exposed data had been identified, it advised vigilance and provided guidance on safeguarding personal information. The college expressed regret for the incident and emphasized implementing measures to prevent future occurrences, though specific technical or procedural changes were not detailed in public communications. Notification letters were dispatched directly to individuals with available addresses, and the public announcement was issued on December 29, 2020, over four months after the breach was discovered.

Sources
Sources available to members
2 sources