MalwarePhishingRansomwareData EncryptedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
The Christian Brothers Academy of Albany
bd_8c3c1855bee4158c · schema v1 · pii pii-v1
Full breach record for The Christian Brothers Academy of Albany →Christian Brothers Academy notified South Carolina residents of a June 2025 cyberattack involving a phishing attack that led to a ransomware deployment. Unauthorized actors accessed files potentially containing names, addresses, financial info, driver's license, and passport numbers. CBA contained the breach, did not pay ransom, engaged forensic investigators, reset passwords, implemented MFA, and provided two years of credit monitoring.
Leak gap clock⏱ Leak >30d10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by interlock about this victim predates this filing by 63 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0b013548a06f040cLeak Siteinterlockfiled 2025-06-12(64d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_0878e0e13414488dIndiana State AGfiled 2025-08-15Verified
- bd_abcb26b62c89b3b1Maine State AGfiled 2025-08-15Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20Christian%20Brothers%20Academy.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2025
- Raw hash
- 1d5b98a3b5da7ba61c1dda8eab63bf9813043d4e6978065f9c28ea9b6730fb36
Reporting entity
- Name
- The Christian Brothers Academy of Albanynorm: the christian brothers academy of albany
Victim entity
- Name
- The Christian Brothers Academy of Albanynorm: the christian brothers academy of albany
Incident
- Discovered
- Jun 4, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.