Lewis and Clark Community College
Incident posture
Linked entities
- Victim
- Lewis and Clark Community College
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Lewis and Clark Community College experienced a cyberattack that disrupted IT systems and services across its campuses. Attackers exfiltrated data from the college’s file storage and later posted a portion of it on the dark web, including personal information such as social security numbers, passport details, and other sensitive records. The breach led to instances of fraudulent tax filings using compromised social security numbers. In response, the college engaged external forensic experts to analyze the stolen data and began providing free credit monitoring and identity restoration services to current and former students, employees, and others potentially affected. Efforts to restore systems from backups continued while the investigation proceeded to determine the full scope of the exposed information.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 3 2023 Lewis & Clark College experienced an IT security incident that disrupted systems and services across its campuses; the attack was characterized as ransomware carried out by a group known for similar incidents against educational institutions. Following guidance from law enforcement and external cybersecurity experts the college chose not to pay a ransom and instead began rebuilding its IT environment from regularly maintained backups while simultaneously engaging a forensic firm to assess whether protected or sensitive data had been compromised. The forensic team reported that the illegally obtained data had been retrieved from the college’s LC Files network drive and that there was no evidence to suggest that other core systems such as Workday, Colleague or Nelnet had been affected; they also noted that some employees had reported fraudulent tax filings using their social security numbers. As part of the response the college issued mandatory password resets with specific complexity requirements, deployed Multi‑Factor Authentication for its GlobalProtect VPN, rolled out Google Plus licenses to all staff and faculty, and made credit monitoring and identity restoration services available at no cost to current students and employees, later extending the same offer to former students and employees from the previous ten years. The college also communicated details about how to place fraud alerts, security freezes and obtain free credit reports, and provided information regarding passport data that may have been included in the compromised material in accordance with U.S. State Department guidance. Most IT systems have since been restored, with the Pionet secure wifi network and WebAdvisor password‑change functionality remaining unavailable while services such as Pionet‑Guest wifi, L&C websites, printing, VPN with MFA, Workday, Slate, Panopto, StarRez, on‑campus phone, GMail and Google Workspace, Zoom, Maxient, dining, online facilities work orders, classroom technology, Handshake, Salesforce, Box, GetInclusive trainings, GivePulse, Colleague and Informer, WebAdvisor and Self Service, LC Files, Moodle, EMS, NuPark, Explorance Blue, GoAnywhere, ExLibris, Secure Forms server, Courseleaf, CBORD, Salesforce/Colleague integration and centrally managed licenses for ESRI ArcGIS, SPSS and Mathematica have been restored or remain operational; the college’s incident webpage was last updated on September 18 2023.
The ongoing investigation involves a methodical review of the stolen data to determine the full scope of any personal information that may have been exposed, and the college has stated that it will issue formal written notification to any individual whose protected information is confirmed to have been acquired once the review is complete, in accordance with applicable state and federal laws. To date the college has found no evidence that the compromised data has been used for identity theft or financial fraud, but it continues to work with its external forensic partner to analyze the material and to provide updates through a series of community emails that detail the status of the review, the steps taken to secure the environment, and the availability of support services such as Experian‑based credit monitoring, identity restoration and identity insurance. The college has also reminded community members to report any suspicious communications to [email protected] and has made enrollment forms and instructions for the offered services readily accessible via its Google‑based portal. No further speculative statements about the attack’s origins or potential future impacts are included in the available source material.
Sources
Sources available to members: 1 source.