OXFAM-AMERICA, INC.
bd_6f7cbe70339f197e · schema v1 · pii pii-v1
Full breach record for OXFAM-AMERICA, INC. →Oxfam America Inc. notified the NH AG of a ransomware attack discovered March 23, 2020. APT41 allegedly exploited Manage Engine to access HR data (names, SSNs) of 23 NH residents. Oxfam engaged LIFARS forensics, shut down Manage Engine, and reported to the Secret Service. Credit monitoring offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 8, 2020
Begins
Mar 23, 2020
Discovered
Apr 20, 2020
Filed
vs. sector median
15 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_b5dfa957a42f182e2020-04-21 · +1dVerified
- Indiana State AGbd_de8929291d9254632020-04-27 · +7dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Apr 20 (NH), last Apr 27 (IN) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.