MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICFINANCIALLowContained
NORTHWEST FOUNDATION, INC.
bd_0a557aa8ecb3a0a0 · schema v1 · pii pii-v1
Full breach record for NORTHWEST FOUNDATION, INC. →Northwest Foundation, Inc. reported a data security incident involving its service provider, Blackbaud, Inc. A ransomware attack on Blackbaud in May 2020 resulted in the exfiltration of a subset of client data, including Northwest Foundation's. The accessed data included names, titles, dates of birth, contact details, and philanthropic history. Financial and SSN data were encrypted and not accessed. The cybercriminal's ransom demand was met by Blackbaud, who asserts the data was destroyed.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-192817
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 7, 2020
- Raw hash
- 207b47d5b44ec8f3cb0aea1d5aeb39e144568e5c923a83720da3a13fd63af7d2
Reporting entity
- Name
- NORTHWEST FOUNDATION, INC.norm: northwest foundation
Victim entity
- Name
- NORTHWEST FOUNDATION, INC.norm: northwest foundation
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.