MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Vermont Student Assistance Corporation
bd_08c27a98ee1b1bf4 · schema v1 · pii pii-v1
Full breach record for Vermont Student Assistance Corporation →Vermont Student Assistance Corporation (VSAC) notified California AG of a breach involving its third-party vendor, Blackbaud, Inc. A ransomware incident at Blackbaud resulted in the encryption of systems and the unauthorized removal of a VSAC database backup containing names and Social Security Numbers. The incident occurred between Feb 7 and May 20, 2020. VSAC offered 12 months of credit monitoring via Experian.
California clockDiscovered Jul 16, 2020 → Notified Sep 25, 202071d ✗ CA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2c1946e3a02b4317Maine State AGfiled 2020-09-25Candidate
- bd_79f77c4712b37181Montana State AGfiled 2020-10-04(9d gap)Verified by operator
- bd_bca2d0e8282fb4bcCalifornia State AGfiled 2020-09-04(21d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194530
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 25, 2020
- Raw hash
- 065e04b15ff957c5e2e6c5f811936dc73452497bbd4718698f63e704c1b2fd7c
Reporting entity
- Name
- Vermont Student Assistance Corporationnorm: vermont student assistance
Victim entity
- Name
- Vermont Student Assistance Corporationnorm: vermont student assistance
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- Sep 25, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying state and federal regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- CA 60-day late · 71d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 16, 2020→ Notified: Sep 25, 202071d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.