MalwareHealthcareHealthcareRansomwareCapture Stored DataSupply Chain (3P Vendor)Ransom DemandedData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowResolved
Emanate Health Foundation
bd_b3ca2988bd532617 · schema v1 · pii pii-v1
Full breach record for Emanate Health Foundation →Emanate Health Foundation notified California residents of a ransomware attack on its third-party provider Blackbaud. The cybercriminal accessed a Foundation backup file hosted on Blackbaud's servers between February 7, 2020 and May 20, 2020, exfiltrating data including names, addresses, birthdates, gender, phone numbers, emails, and hospital department locations. No SSNs, credit card, or bank account data were involved.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194003
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2020
- Raw hash
- 83263fc4ebba70c1f8666a175c87f1680119ed524bb60de41914677609bbf3af
Reporting entity
- Name
- Emanate Health Foundationnorm: emanate health
Victim entity
- Name
- Emanate Health Foundationnorm: emanate health
- Industry
- Healthcarellm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Blackbaud
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.