THE BALTIMORE MUSEUM OF ART, INC.
bd_7d2c973969ec3837 · schema v1 · pii pii-v1
Full breach record for THE BALTIMORE MUSEUM OF ART, INC. →2 incidents on fileThe Baltimore Museum of Art notified the NH AG of a security event where unauthorized third parties accessed employee email accounts using stolen credentials between April 27-28, 2020. The attacker sent phishing emails to harvest Office 365 credentials and attempted to run a fake payroll, which was stopped by the payroll provider. One NH resident was affected. BMA reset passwords, enabled MFA, and provided credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 27, 2020
Begins
Apr 28, 2020
Discovered
May 11, 2020
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_6aa044046b048bde2020-05-07 · +4dVerified
- Indiana State AGbd_b3d6b9852db97a6d2020-05-07 · +4dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.