On March 3, 2023, Lewis & Clark College experienced a significant cybersecurity incident, leading to unauthorized access to its network. The college detected this intrusion promptly and discovered that certain data maintained on their servers was compromised. The breach appears to have been part of a targeted attack, where unidentified bad actors successfully extracted data from the college's network environment around February 28, 2023.
Upon discovering the breach, the college took immediate steps to secure its network. They engaged external cybersecurity professionals to assist in the investigation and to prevent further unauthorized access. Their thorough investigation concluded that personal information stored on the impacted servers was involved. By February 24, 2024, it was confirmed that sensitive data, including personal details of individuals associated with the college, had been compromised.
In response to the incident, Lewis & Clark College has significantly ramped up its security measures. The college has implemented additional security improvements recommended by cybersecurity experts to fortify its network against future attacks. These enhancements are part of an ongoing effort to strengthen their cybersecurity posture and to safeguard the personal information of their community.
The specific types of personal information exposed during the breach were not detailed in the initial reports. However, the college has been transparent about the nature of the data accessed and is in the process of notifying affected individuals directly.
Lewis & Clark College is offering complimentary credit monitoring services to all individuals potentially impacted by this breach. These services include Single Bureau Credit Monitoring, which will alert users to any significant changes in their credit file. To enroll in these services, affected parties are encouraged to visit the provided enrollment link and use the unique code provided in their notification letter.
Furthermore, the college advises everyone to remain vigilant by regularly reviewing their financial account statements and credit reports. If any suspicious or irregular activity is detected, it should be reported immediately to the relevant financial institution.
For more detailed information about the breach and advice on how to protect your personal information, please visit the California Attorney General’s disclosure page.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.