DisclosureLens
HackingProfessional ServicesProfessional ServicesStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIdentity (basic)Government IDMediumContained

Big Brothers Big Sisters

bd_326cb9b1491d0acf · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 15, 2023

Filed

Nov 22, 2023

To disclose

7 days

Affected

Not disclosed

Linked

8 filings

Confidence

64%
Full breach record for Big Brothers Big Sisters

Big Brothers Big Sisters of America (BBBSA) notified Delaware AG on November 22, 2023, regarding a cybersecurity incident occurring on March 28, 2023. An unauthorized actor accessed BBBSA's network and downloaded files containing personal information, including Social Security numbers and driver's license numbers. BBBSA notified the FBI, engaged external cybersecurity professionals, and is offering 12 months of credit monitoring and fraud assistance to affected individuals. The investigation was completed, and access was contained.

Incident timeline

undetected · 232 days
discovery → filing · 7 days

Mar 28, 2023

Begins

Nov 15, 2023

Discovered

Nov 22, 2023

Filed

vs. sector median

17 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 5d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Nov 21 (MT), last Nov 27 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.