Bay Bridge Administrators
bd_3e79034e4a2a5985 · schema v1 · pii pii-v1
Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Redalert on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 22, 2022
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Massachusetts State AGbd_0bb7d657c86dba1b2022-12-29 · +98dVerified by operator
- New Hampshire State AGbd_41fc712ff0e60b1f2022-12-29 · +98dVerified
- Montana State AGbd_76eac57a123a96582022-12-29 · +98dVerified by operator
- Washington State AGbd_867688de2ddd81a72022-12-29 · +98dVerified
Show 6 more filings ↓Show fewer ↑up to 103d gap
- California State AGbd_868a3feb8eb3d9422022-12-29 · +98dVerified by operator
- Indiana State AGbd_b8b0124bb50f47962022-12-29 · +98dVerified
- Oregon State AGbd_d303951afc2ff8462022-12-29 · +98dVerified by operator
- Maine State AGbd_e3985ce504723a982022-12-29 · +98dVerified by operator
- HHS OCRbd_2076fcfdead4ed372022-12-30 · +99dVerified
- South Carolina State AGbd_aa72d65a4a6c499e2023-01-03 · +103dVerified by operator
Filing propagation · 11 filings · 10 states
View merged incident ↗Pattern: first filing Sep 22, last Jan 3 (SC) — a 103-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
redalert
According to ransomware.live, RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks.