DisclosureLens
MalwareEducationEducationRansomwareData MishandlingSupply Chain (3P Vendor)Data ExfiltratedRansom DemandedMulti-Stage ChainIdentity (basic)PIILowActive

Buffalo State College Foundation

bd_9d3e1524f5ff5a2e · schema v1 · pii pii-v1

Severity

Low

Discovered

May 20, 2021

Filed

Jun 16, 2021

To disclose

27 days

Affected

536state residents only

Confidence

69%
Full breach record for Buffalo State College Foundation

Buffalo State College Foundation reported a ransomware incident involving third-party provider Blackbaud. Data was exfiltrated between Feb 7 and May 20, 2020. The Foundation learned on May 20, 2021 that Washington residents' names and DOBs may have been accessed. 536 residents affected. Ransom was paid to threat actor for data destruction.

Washington clock WA AG ≤30d27 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 468 days
discovery → filing · 27 days

Feb 7, 2020

Begins

May 20, 2021

Discovered

Jun 16, 2021

Filed

vs. sector median

6 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed536 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.