MalwareRansomwareSupply Chain (3P Vendor)Data EncryptedRansom DemandedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Fort Hays State University Foundation
bd_342acd5f7ba86b64 · schema v1 · pii pii-v1
Full breach record for Fort Hays State University Foundation →Fort Hays State University Foundation reported a data breach involving its third-party vendor, Blackbaud, Inc. The incident involved an attempted ransomware attack on Blackbaud's network between February 7, 2020, and May 20, 2020. Backup files containing names and Social Security numbers of alumni and donors were exfiltrated. Blackbaud paid a ransom and confirmed the destruction of the files. The Foundation notified affected individuals in February 2021, offering two years of complimentary identity monitoring services.
California clockDiscovered May 20, 2020 → Notified Feb 7, 2021263d ✗ CA 60-day late47 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_05a22e6205fcfbfbOregon State AGfiled 2021-04-16Candidate
- bd_f2bfd9f35ba072fcMaine State AGfiled 2021-04-16Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540001
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 16, 2021
- Raw hash
- 7bb21e73ea9dceb43c02b6523c0f6567dc79a8322c68061c4c5c5e8e975cd451
Reporting entity
- Name
- Fort Hays State University Foundationnorm: fort hays state university
Victim entity
- Name
- Fort Hays State University Foundationnorm: fort hays state university
Incident
- Discovered
- May 20, 2020
- Materiality determined
- —
- Notification sent
- Feb 7, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Office of the Attorney General
- Third party
- via Blackbaud, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 47 weeks(331 days from discovery to filing)
- Compliance flags
- CA 60-day late · 263d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 20, 2020→ Notified: Feb 7, 2021263d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.