[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqwI9f1qU9jStAkyPcl1NQTOD8ewjxyzWgBX5e1awzPg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":18,"dataClasses":19,"description":23,"source":24,"isVerified":4,"isSpamList":25,"isSensitive":4,"processingStatus":26,"logoUrl":27,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":28},"6a6727a6bcf4c1adc8856c67","NorthwestIowaCommunityCollege2025","Northwest Iowa Community College 2025 Data Breach","northwest-iowa-community-college-2025","nwicc.edu",{"name":12,"sector":13,"country":14,"website":10},"Northwest Iowa Community College","Education","United States","2025-11-24T00:00:00.000Z","2026-07-27T09:40:54.622Z",0,null,[20,21,22],"Personal information","First and last names","Social Security numbers","\u003Cp>\u003Cstrong>The Northwest Iowa Community College 2025 data breach\u003C\u002Fstrong> involved unauthorized activity in college computer systems from November 24 through November 26, 2025, during which a limited amount of information may have been accessed or downloaded. NCC detected the activity November 26, secured its network, and engaged outside specialists to determine the event's nature and scope.\u003C\u002Fp>\n\u003Cp>The official filing with the Iowa Attorney General confirms that potentially affected information combined an individual's name with a Social Security number. After address-verification work concluded July 6, 2026, NCC determined that 16,004 Iowa residents were potentially affected. Because no nationwide total was disclosed, LeakData treats that figure as a verified lower bound.\u003C\u002Fp>\n\u003Ch2>How Was the NCC Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the official “Notice of Data Security Event” sent for Northwest Iowa Community College to the Iowa Attorney General Consumer Protection Division on July 8, 2026. It describes the access period, discovery date, May 29 data-review result, July 6 address verification, 16,004-Iowa-resident count, name and SSN scope, and mailed notifications beginning that same day.\u003C\u002Fp>\n\u003Cp>Claim Depot links the official Iowa filing to the college profile and independently summarizes the November 24–26 access window, 16,004-resident scope, name and SSN fields, and 12 months of Cyberscout services. The two sources align on the core facts. LeakData does not add the college's annual student population or total alumni population to the affected-person count.\u003C\u002Fp>\n\u003Ch2>What Happened From November 24 Through November 26, 2025?\u003C\u002Fh2>\n\u003Cp>NCC became aware of unauthorized activity in its computer systems on or around November 26. It quickly secured the network and engaged third-party specialists. The investigation found that a limited amount of information may have been accessed or downloaded without authorization from November 24 through November 26. The source's modal wording matters: it does not establish that every file was definitely copied.\u003C\u002Fp>\n\u003Cp>The public filing does not disclose the initial-access method, malware, actor identity, ransom demand, data publication, or number of files involved. The event has a confirmed three-day window, but the way access was obtained remains undisclosed. LeakData therefore does not fill technical gaps with assumptions and describes only the unauthorized system activity substantiated by the college.\u003C\u002Fp>\n\u003Ch2>What Personal Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The official regulator letter defines the potentially impacted information as an individual's name in combination with a Social Security number. That pairing may increase risks involving identity theft, new credit accounts, fraudulent tax returns, and targeted social engineering built around accurate identity details. The word “potentially” must be preserved; notification does not prove that misuse occurred.\u003C\u002Fp>\n\u003Cp>The sources do not list email addresses, passwords, usernames, telephone numbers, physical addresses, dates of birth, student IDs, grades, course records, disciplinary records, bank accounts, payment cards, health data, or biometrics as confirmed incident fields. Standard advice in the protection appendix about some broader information types does not make those types part of this event.\u003C\u002Fp>\n\u003Ch2>What Steps Are Appropriate After SSN Exposure?\u003C\u002Fh2>\n\u003Cp>Recipients should review reports from the three major credit bureaus for unfamiliar accounts, inquiries, or address changes. A free security freeze limits a new creditor's access to the report, while a one-year fraud alert asks businesses to strengthen identity checks. An IRS Identity Protection PIN may help reduce tax-identity misuse, and suspicious tax correspondence should be verified through an official IRS channel.\u003C\u002Fp>\n\u003Cp>An unexpected contact claiming to represent NCC or Cyberscout should not receive a full SSN, credit-bureau PIN, password, or one-time code. Use only the unique enrollment code and official address contained in the individual notice. A caller who knows a name and part of an SSN is not authenticated by that knowledge; obtain any callback number independently.\u003C\u002Fp>\n\u003Ch2>How Did NCC Respond?\u003C\u002Fh2>\n\u003Cp>The college secured its network, conducted a forensic investigation, and reviewed and enhanced its data-security and cybersecurity policies. Its comprehensive review of potentially impacted information was completed May 29, 2026. NCC then used a National Change of Address search to confirm current contact details, received those results July 6, and began mailing notices July 8.\u003C\u002Fp>\n\u003Cp>All notified individuals were offered 12 months of complimentary single-bureau credit monitoring, a credit report, a credit score, and proactive fraud assistance through Cyberscout. Enrollment must be completed within 90 days of the letter and requires the unique activation code. NCC also established a dedicated weekday call center operating from 8 a.m. to 8 p.m. Eastern Time; the number is masked in the public sample.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and How Should the Count Be Read?\u003C\u002Fh2>\n\u003Cp>The official Iowa filing expressly establishes 16,004 potentially affected Iowa residents. It does not define the value as a deduplicated nationwide total, so LeakData stores it as a lower bound. The college's annual student population, employee count, alumni network, or information-system user count must not be substituted for the number of people affected by this event.\u003C\u002Fp>\n\u003Cp>A recipient should retain the notice, activate the complimentary protection in time, and monitor credit and tax records over the longer term because an SSN does not expire. People who received no letter should not assume impact merely because they once had a relationship with the college. LeakData holds no raw incident files or person records for this event; a search result has meaning only when supported by locally audited data.\u003C\u002Fp>","Official Iowa Attorney General filing confirming unauthorized NCC system activity and possible access to names with Social Security numbers",false,"completed","\u002Fuploads\u002Flogo\u002Fnwicc_edu.png","Low"]