HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
The Columbus Foundation
bd_1c954e0a4855b2ea · schema v1 · pii pii-v1
Full breach record for The Columbus Foundation →The Columbus Foundation, a nonprofit in Columbus, OH, disclosed a breach in early July 2023 where an unauthorized party posted direct internet links to a limited portion of internal data from its Gifts of Kindness and Emergency Assistance programs. The exposure included applicant PII. The breach affected one New Hampshire resident. TCF discovered the incident on August 8, 2023, removed the links, and notified the individual on September 8, 2023. No evidence of misuse was found. TCF provided 12 months of credit monitoring via Experian.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6e85b5718c2dbf4cMontana State AGfiled 2023-09-11Candidate
- bd_fae7d45522d0c5c5Vermont State AGfiled 2023-09-08(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/columbus-foundation-20230911.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2023
- Raw hash
- 5eb3e88019d3dfb65758c6f36a887912ac9488490a2b9ca6b2d6ca258bd41869
Reporting entity
- Name
- The Columbus Foundationnorm: the columbus
Victim entity
- Name
- The Columbus Foundationnorm: the columbus
Incident
- Discovered
- Aug 8, 2023
- Materiality determined
- —
- Notification sent
- Sep 8, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.