Clover Park School District
bd_b303bc80ef0b7c73 · schema v1 · pii pii-v1
Full breach record for Clover Park School District →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Grief on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 26, 2021
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_19ef18cc421585992021-07-12 · +47dVerified by operator
- Indiana State AGbd_1b88bb529743635b2021-07-12 · +47dVerified
- Washington State AGbd_2291a38c68be161b2021-07-12 · +47dCandidate
- Maine State AGbd_cac688e35ccd9ae82021-07-12 · +47dVerified
Show 2 more filings ↓Show fewer ↑up to 51d gap
- Montana State AGbd_fc31907b6e6b28fc2021-07-12 · +47dVerified
- New Hampshire State AGbd_69338cea1e398c622021-07-16 · +51dVerified
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing May 26, last Jul 16 (NH) — a 51-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
grief
According to ransomware.live, Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".