DisclosureLens
MalwareOtherRansomwareSupply Chain (3P Vendor)Data EncryptedTargetedIdentity (basic)MediumContained

Heifer International

bd_527d0749f8d0a81c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 16, 2020

Filed

Aug 28, 2020

To disclose

6 weeks

Affected

4,026state residents only

Confidence

65%
Full breach record for Heifer International4 incidents on file

Heifer International notified individuals of a ransomware incident affecting its third-party vendor, Blackbaud, Inc. The incident occurred in May 2020. Blackbaud, a CRM host for nonprofits, detected the ransomware and locked out the actor. Heifer International investigated and determined that affected records contained names and other personal information. No specific access to Heifer's data was confirmed by Blackbaud. The notice was sent on July 16, 2020.

South Carolina clock SC CRA notice due6 weeks discovery → filing
notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

undetected · 76 days
discovery → filing · 6 weeks / 43 days

May 1, 2020

Begins

Jul 16, 2020

Discovered

Aug 28, 2020

Filed

vs. sector median

2 wks faster

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,026 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.