BLACKBAUD, INC.
bd_9a8f3f015273b296 · schema v1 · pii pii-v1
Full breach record for BLACKBAUD, INC. →Helen Keller International (HKI) notified the New Hampshire Attorney General of a data breach involving its third-party vendor, Blackbaud, Inc. A ransomware attack occurred between February 7, 2020, and May 20, 2020. Blackbaud paid a ransom and confirmed the destruction of compromised data. HKI's forensic review determined that one New Hampshire resident's financial account information, usernames, passwords, and Social Security numbers were potentially exposed, though encrypted. HKI notified the affected individual on January 19, 2021, and provided one year of credit monitoring.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/helen-keller-international-20210122.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 22, 2021
- Raw hash
- 1b0ed88184b3983f1a94c7be221b21a33b1e5c127b7bf58037aac280b845cf27
Reporting entity
- Name
- Helen Keller Internationalnorm: helen keller
- Domain
- hki.org
Victim entity
- Name
- BLACKBAUD, INC.norm: blackbaud
- Domain
- blackbaud.com
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- Jan 19, 2021
- Affected individuals
- 1
- Data types
- FINANCIAL_ACCOUNTCREDENTIALSIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Third party
- via Blackbaud, Inc.service provider
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(190 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.