MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Stetson University Athletics
bd_6d112560d028361e · schema v1 · pii pii-v1
Full breach record for Stetson University Athletics →Stetson University, Inc. reported a ransomware attack on third-party vendor Blackbaud's systems. The incident occurred between February 7, 2020, and May 20, 2020. Blackbaud, a fundraising software provider, confirmed that data was exfiltrated from a backup file. Stetson notified affected individuals, including approximately 115 Rhode Island residents, offering one year of credit monitoring. The vendor paid the ransom to ensure the destruction of the stolen backup file.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed115 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-195773
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2020
- Raw hash
- e34966c061bc3c62ad34cbb24429de2eb07fbe439aa8c518bea026ced140e342
Reporting entity
- Name
- Stetsonnorm: stetson
- Domain
- stetson.com
Victim entity
- Name
- Stetson University Athleticsnorm: stetson university athletics
- Domain
- gohatters.com
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 115
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.