DisclosureLens
MalwareEducationEducationRansomwareRoyalRansom DemandedRansom PaidData ExfiltratedData EncryptedCustomer Data InvolvedActor NamedIdentity (basic)Government IDFinancial accountCredentialsPHIHealth (basic)MediumContained

Big Brothers Big Sisters

bd_5eb645451e1676d1 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 28, 2023

Filed

Nov 21, 2023

To disclose

34 weeks

Affected

458state residents only

Linked

8 filings

Confidence

68%
Full breach record for Big Brothers Big Sisters

Big Brothers Big Sisters of America (BBBSA) reported a ransomware incident on March 28, 2023, attributed to the 'Royal' threat actor group. Unauthorized actors accessed and exfiltrated sensitive data including names, SSNs, driver's licenses, financial account details, credentials, and PHI. BBBSA paid a ransom to recover the data. 458 Montana consumers were affected. BBBSA engaged forensic experts, notified the FBI via IC3, and implemented extensive security enhancements including MFA, EDR, and enhanced training.

Incident timeline

discovery → filing · 34 weeks / 238 days

Mar 28, 2023

Begins

Mar 28, 2023

Discovered

Nov 21, 2023

Filed

vs. sector median

+24 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 6d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Nov 21 (MT), last Nov 27 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.