AccidentalMisconfigurationSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Cathedral High School
bd_9fa799992494623b · schema v1 · pii pii-v1
Full breach record for Cathedral High School →Cathedral Catholic High School (operating under the Diocese of Charlotte) reported a data breach involving third-party vendor Blackbaud. Legacy backup files containing names, addresses, phone numbers, and Social Security Numbers (or Tax ID numbers) were exposed because they were not destroyed or encrypted after migration. The incident was detected in May 2020, with notifications sent in November 2020. Affected individuals were offered 24 months of credit monitoring and fraud resolution services.
California clockDiscovered May 1, 2020 → Notified Nov 30, 2020213d ✗ CA 60-day late31 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_88ccf408a93fdd4cCalifornia State AGfiled 2021-01-22(47d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196814
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2020
- Raw hash
- 93d66d194027b7388cf0ebc46295184b4bad5558315e9e16934aded9f0746db1
Reporting entity
- Name
- The official news source of the Diocese of Charlotte, NCnorm: the official news source of the diocese of charlotte nc
- Domain
- catholicnewsherald.com
Victim entity
- Name
- Cathedral High Schoolnorm: cathedral high school
- Domain
- cathedralhs.org
Incident
- Discovered
- May 1, 2020
- Materiality determined
- —
- Notification sent
- Nov 30, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1119 Automated Collection
- Threat actor
- Partner
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Third party
- via Blackbaud Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 31 weeks(219 days from discovery to filing)
- Compliance flags
- CA 60-day late · 213d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 1, 2020→ Notified: Nov 30, 2020213d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.