HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Crystal Stairs
bd_3e0448157e5e3e52 · schema v1 · pii pii-v1
Full breach record for Crystal Stairs →Crystal Stairs, Inc. notified California residents of a data breach involving their third-party software provider, Blackbaud, Inc. The incident occurred in May 2020 when cybercriminals accessed Blackbaud systems. Affected data included names and Social Security numbers or tax identification numbers. Crystal Stairs is offering 12 months of identity protection via TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193480
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 26, 2020
- Raw hash
- c763d07066b49365686782d6c4dea1fc17d25a5a62972cc536caa8960aa402c2
Reporting entity
- Name
- Crystal Stairsnorm: crystal stairs
- Domain
- crystalstairs.org
Victim entity
- Name
- Crystal Stairsnorm: crystal stairs
- Domain
- crystalstairs.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notifying state regulators of this incident
- Third party
- via Blackbaud, Inc.
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.