DisclosureLens
MalwareTechnologyProfessional ServicesInformationRansomwareData EncryptedRansom DemandedSupply Chain (3P Vendor)Customer Data InvolvedFinancial accountCredentialsGovernment IDMediumContained

Helen Keller International

bd_9a8f3f015273b296 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 16, 2020

Filed

Jan 22, 2021

To disclose

27 weeks

Affected

1state residents only

Confidence

66%
Full breach record for Helen Keller International3 incidents on file

Helen Keller International (HKI) notified the New Hampshire Attorney General of a data breach involving its third-party vendor, Blackbaud, Inc. A ransomware attack occurred between February 7, 2020, and May 20, 2020. Blackbaud paid a ransom and confirmed the destruction of compromised data. HKI's forensic review determined that one New Hampshire resident's financial account information, usernames, passwords, and Social Security numbers were potentially exposed, though encrypted. HKI notified the affected individual on January 19, 2021, and provided one year of credit monitoring.

Incident timeline

undetected · 160 days
discovery → filing · 27 weeks / 190 days

Feb 7, 2020

Begins

Jul 16, 2020

Discovered

Jan 22, 2021

Filed

vs. sector median

+8 wks slower

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.