HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
New York Blood Center Enterprises
bd_55ee795695b6f651 · schema v1 · pii pii-v1
Full breach record for New York Blood Center Enterprises →New York Blood Center Enterprises disclosed a cybersecurity incident occurring between January 20 and January 26, 2025, where an unauthorized party accessed internal systems. The breach affected employee records (SSN, driver's license, financial data) and donor records (demographic info, pre-screening questionnaires, infectious disease test results). The organization engaged cybersecurity partners, enhanced security protocols, and offered one year of Experian IdentityWorks monitoring to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_4cc7e1640f2d1cc8Maine State AGfiled 2025-09-05Candidate
- bd_69f70ca1ca2f3c49Oregon State AGfiled 2025-09-05Verified
- bd_8062973a873e99bfNew Hampshire State AGfiled 2025-09-05Verified
- bd_8a44078c684109ddIndiana State AGfiled 2025-09-05Verified
Show 4 more filings ↓Show fewer ↑up to 4d gap
- bd_98a5c223b0a3fe78Montana State AGfiled 2025-09-05Verified by operator
- bd_c5001b57e805910aCalifornia State AGfiled 2025-09-05Verified
- bd_ef3dd2e5e9fec429Washington State AGfiled 2025-09-05Verified by operator
- bd_3c6450c461889c65Texas State AGfiled 2025-09-09(4d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/NYBCe-Attachment.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2025
- Raw hash
- 55e532496186509bdda06e9894e7fcd887bea9e8bf88ab2b32c26b8cf6e6cd44
Reporting entity
- Name
- New York Blood Center Enterprisesnorm: new york blood center
Victim entity
- Name
- New York Blood Center Enterprisesnorm: new york blood center
Incident
- Discovered
- Jan 26, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 32 weeks(222 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.