Big Brothers Big Sisters
bd_5eb645451e1676d1 · schema v1 · pii pii-v1
Full breach record for Big Brothers Big Sisters →Big Brothers Big Sisters of America (BBBSA) reported a ransomware incident on March 28, 2023, attributed to the 'Royal' threat actor group. Unauthorized actors accessed and exfiltrated sensitive data including names, SSNs, driver's licenses, financial account details, credentials, and PHI. BBBSA paid a ransom to recover the data. 458 Montana consumers were affected. BBBSA engaged forensic experts, notified the FBI via IC3, and implemented extensive security enhancements including MFA, EDR, and enhanced training.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 28, 2023
Begins
Mar 28, 2023
Discovered
Nov 21, 2023
Filed
vs. sector median
+24 wks slower
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Washington State AGbd_00be541af1bd1c262023-11-22 · +1dVerified
- Delaware State AGbd_326cb9b1491d0acf2023-11-22 · +1dVerified
- Vermont State AGbd_966c4007faa4a2f82023-11-22 · +1dVerified
- Maine State AGbd_bc1e14d477ece04a2023-11-22 · +1dVerified
Show 3 more filings ↓Show fewer ↑up to 6d gap
- California State AGbd_d7ba25bbba1c16132023-11-22 · +1dVerified
- New Hampshire State AGbd_f793da00c6d196772023-11-22 · +1dVerified
- Massachusetts State AGbd_b0099b4ccb4645092023-11-27 · +6dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Nov 21 (MT), last Nov 27 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.