UNIVERSITY OF DETROIT MERCY
bd_aa80fb8834d55706 · schema v1 · pii pii-v1
Full breach record for UNIVERSITY OF DETROIT MERCY →3 incidents on fileUniversity of Detroit Mercy notified individuals of a data security incident involving its third-party vendor, Blackbaud. A ransomware attack on Blackbaud's systems resulted in the exfiltration of data between February 7, 2020, and May 20, 2020. The compromised data may have included full names and Social Security numbers. Blackbaud paid the ransom to ensure the destroyed backup file was permanently deleted. The university engaged external cybersecurity professionals and offered one year of complimentary credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 7, 2020
Begins
Jul 16, 2020
Discovered
Aug 17, 2020
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_5345177a0577985b2020-08-14 · +3dVerified
- Indiana State AGbd_d8e3aff7bff7bd232020-08-14 · +3dVerified
- New Hampshire State AGbd_6db59533b1a2fa102020-08-24 · +7dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Aug 14 (MA), last Aug 24 (NH) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.