MalwareRansomwareData EncryptedRansom DemandedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
BLACKBAUD, INC.
bd_aa9fecc3f7e2bbab · schema v1 · pii pii-v1
Full breach record for BLACKBAUD, INC. →Wayne State Foundation notified New Hampshire AG of a ransomware attack on third-party provider Blackbaud. The attack occurred between Feb 7 and May 20, 2020. WSF discovered 2 NH residents potentially impacted via SSN/DOB in the database. Blackbaud paid ransom and confirmed data destruction. WSF offered 1 year of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/wayne-state-foundation-20210121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2021
- Raw hash
- e0c673599477c76181b50e435a67edcd0f3fabb2f62188a3eb452cfcb7fcfd6a
Reporting entity
- Name
- Wayne State Foundationnorm: wayne state
Victim entity
- Name
- BLACKBAUD, INC.norm: blackbaud
- Domain
- blackbaud.com
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- Jan 13, 2021
- Affected individuals
- 2
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed Security Incident Notification with New Hampshire Office of Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.