DisclosureLens
MalwareOtherRansomwareCapture Stored DataRansom DemandedRansom PaidData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDownstream VictimsIdentity (basic)PIILowResolved

American Symphony Orchestra League

bd_5bbb3b52b74f4a4b · schema v1 · pii pii-v1

Severity

Low

Discovered

—

Filed

Oct 5, 2020

To disclose

—

Affected

Not disclosed

Confidence

79%
Full breach record for American Symphony Orchestra League →5 incidents on file

Blackbaud, a database vendor serving the League of American Orchestras (American Symphony Orchestra League), suffered a ransomware attack in which a cybercriminal removed a backup file containing donor/constituent personal information (names, addresses, phone numbers, email, demographic data, donation history). No credit card, bank account, or SSN data was involved. Blackbaud paid the ransom and obtained confirmation the data was destroyed. The letter was sent October 2020.

Incident timeline

May 1, 2020

Begins

Oct 5, 2020

Filed

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.