Hackers accessed up to 16 years of Colorado public school student data during a June ransomware attack on the Colorado Department of Higher Education, exposing records tied to students and educators across the state. Reporting said the compromised information included sensitive education data held by the department, making the incident one of the more significant state education-sector breaches in Colorado.
Colorado officials later faced scrutiny for failing to promptly disclose the breach, with reporting indicating the department did not notify affected people and the public as quickly as expected after discovering the intrusion. The delayed disclosure raised concerns about compliance with breach-notification obligations and about how state agencies communicate cyber incidents involving long-retained student records.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
In October 2023, reporting highlighted that the Colorado higher education department had failed to promptly disclose the data breach, drawing attention to delays in notifying affected parties and the public. This marked a governance and response issue beyond the initial intrusion itself.
By August 2023, officials publicly reported that hackers had accessed extensive Colorado public school student data during the June attack, including records spanning roughly 16 years. The disclosure established the breadth of the incident's impact on student information.
In June 2023, the Colorado Department of Higher Education was hit by a ransomware attack that compromised systems holding public school data. Reporting said attackers accessed up to 16 years of student information.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
statescoop.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.