DisclosureLens
MalwareEducationEducationRansomwareData ExfiltratedRansom DemandedRansom PaidSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDMediumContained

Charleston Day School

bd_3a3ce0a6734a7426 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 1, 2020

Filed

Dec 29, 2020

To disclose

35 weeks

Affected

1state residents only

Confidence

66%
Full breach record for Charleston Day School2 incidents on file

Charleston Day School notified the New Hampshire Attorney General of a ransomware incident involving third-party vendor Blackbaud, Inc. The attack occurred between February 7 and May 20, 2020, and was discovered in May 2020. A subset of constituent data, including names and Social Security numbers, was exfiltrated. Blackbaud paid the ransom and confirmed data destruction. One New Hampshire resident was notified on December 29, 2020, and offered two years of credit monitoring.

Incident timeline

undetected · 84 days
discovery → filing · 35 weeks / 242 days

Feb 7, 2020

Begins

May 1, 2020

Discovered

Dec 29, 2020

Filed

vs. sector median

+26 wks slower

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.