Lewis & Clark College faces class action lawsuit over 2023 data breach

PORTLAND, Ore. (KOIN) – Lewis & Clark College is facing a class action lawsuit filed by a former employee, alleging the school failed to protect student and employee data from a 2023 cybersecurity breach, and says the school failed to notify those impacted in a timely manner, according to court documents.

The complaint, filed April 10 — as reported by The Oregonian — alleges negligence, breach of implied contract, and violations of Oregon’s Unlawful Trade Practices Act and asks the court to certify the class action.

According to the complaint, the breach took place around Feb. 28, 2023, and was discovered by the school around March 3, 2023.

Mayor Wheeler’s use of encrypted iMessages costs city $166K

After launching an investigation, the school determined in February 2024 that “unauthorized actors” accessed private information, and began notifying those impacted in April 2024, the complaint says.

In a statement on their website, Lewis & Clark College stated they “immediately took steps to secure the network and mitigate against any additional harm,” and worked with third-party cybersecurity experts to investigate the breach.

The school said they determined identifiable personal information and/or protected health information including names, dates of birth, Social Security numbers, and financial account information, were included in the hack. The school noted they do not have evidence linking the breach to financial fraud or identity theft.

A spokesperson for Lewis & Clark College told KOIN 6 News the school does not comment on pending litigation, noting the school has been open about the data breach.

‘Consent agenda’ was key to ‘hide’ MultCo-AMR contract renewal

“Because Lewis and Clark stored and handled such highly-sensitive private information, it had a duty and obligation to safeguard this information and prevent unauthorized third parties from accessing this data,” the complaint says.

“Lewis and Clark failed to fulfill these obligations, as unauthorized cybercriminals breached Lewis and Clark’s information systems and databases and stole vast quantities of private information,” the complaint continues. “The data breach occurred because Lewis & Clark inexcusably failed to implement reasonable security protections to safeguard its information systems and databases.”

The complaint furthers, “Lewis and Clark’s meager attempt to ameliorate the effects of this data breach with one year of complimentary credit monitoring is woefully inadequate.”

As a result of the breach, the suit says the plaintiff– who received a breach notice from the school — received a “dramatic increase” in spam calls, text messages and emails.

The suit furthers the plaintiff and class action members suffered injuries including lost or diminished value of their private information, out-of-pocket expenses to prevent or recover from identity theft, time needed to investigate unauthorized access to their accounts, and charges associated with their accounts.

KOIN 6 News reached out to the plaintiffs’ attorneys but has not heard back.

For the latest news, weather, sports, and streaming video, head to KOIN.com.