HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Big Brothers Big Sisters
bd_326cb9b1491d0acf · schema v1 · pii pii-v1
Full breach record for Big Brothers Big Sisters →Big Brothers Big Sisters of America (BBBSA) notified Delaware AG on November 22, 2023, regarding a cybersecurity incident occurring on March 28, 2023. An unauthorized actor accessed BBBSA's network and downloaded files containing personal information, including Social Security numbers and driver's license numbers. BBBSA notified the FBI, engaged external cybersecurity professionals, and is offering 12 months of credit monitoring and fraud assistance to affected individuals. The investigation was completed, and access was contained.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_00be541af1bd1c26Washington State AGfiled 2023-11-22Verified
- bd_5298e72032a99f4bDelaware State AGfiled 2023-11-22Verified
- bd_966c4007faa4a2f8Vermont State AGfiled 2023-11-22Verified
- bd_bc1e14d477ece04aMaine State AGfiled 2023-11-22Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_d7ba25bbba1c1613California State AGfiled 2023-11-22Verified
- bd_f793da00c6d19677New Hampshire State AGfiled 2023-11-22Verified
- bd_5eb645451e1676d1Montana State AGfiled 2023-11-21(1d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/12/Big-Brothers-Big-Sisters-of-America.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- f91e23d734f8901fe1ed84decfcafa0200cc78de11225e3b3771e05795759036
Reporting entity
- Name
- Big Brothers Big Sistersnorm: big brothers big sisters
- Domain
- bigs.org
Victim entity
- Name
- Big Brothers Big Sistersnorm: big brothers big sisters
- Domain
- bigs.org
Incident
- Discovered
- Nov 15, 2023
- Materiality determined
- —
- Notification sent
- Nov 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- notified the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.