DisclosureLens
MalwareEducationEducationRansomwareSupply Chain (3P Vendor)Data ExfiltratedData EncryptedCustomer Data InvolvedEducationIdentity (basic)Government IDHighContained

POINT LOMA NAZARENE UNIVERSITY

bd_668e568195e04463 · schema v1 · pii pii-v1

Severity

High

Discovered

Jul 17, 2020

Filed

Sep 23, 2020

To disclose

10 weeks

Affected

1,967state residents only

Confidence

68%
Full breach record for POINT LOMA NAZARENE UNIVERSITY2 incidents on file

Point Loma Nazarene University (PLNU) notified the Washington AG of a ransomware incident affecting its third-party vendor, Blackbaud, Inc. The breach exposed names, dates of birth, and student IDs of 1,967 Washington residents. Data was exfiltrated between April 18 and May 7, 2020. PLNU was notified by Blackbaud on July 17, 2020, and sent notifications to affected individuals on September 23, 2020.

Washington clock WA AG >30d10 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 90 days
discovery → filing · 10 weeks / 68 days

Apr 18, 2020

Begins

Jul 17, 2020

Discovered

Sep 23, 2020

Filed

vs. sector median

+1 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,967 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.