MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICMINORMediumContained
American Council for International Studies
bd_b51c1c9a31d33805 · schema v1 · pii pii-v1
Full breach record for American Council for International Studies →American Council for International Studies (ACIS) disclosed a ransomware incident occurring between May 25 and June 10, 2021. The attacker encrypted systems and exfiltrated data, including names and minor child information. ACIS secured systems, restored access, and notified federal/state regulators. Affected individuals were offered credit monitoring via Experian. Rhode Island residents (195) were explicitly identified; total count undisclosed.
California clockDiscovered Jun 10, 2021 → Notified Dec 3, 2021176d ✗ CA 60-day late25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0cfa5fef00b11ee0Montana State AGfiled 2021-12-03Candidate
- bd_2b22345a0d7b36b3Oregon State AGfiled 2021-12-03Verified
- bd_417f20105b702432Maine State AGfiled 2021-12-03Verified
- bd_ce6f170a133fdcafWashington State AGfiled 2021-12-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548177
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 3, 2021
- Raw hash
- fc2917e414b3edf1b8901982697eef45c776d7256a5910097599b3d7f7151bea
Reporting entity
- Name
- American Council for International Studiesnorm: american council for international studies
Victim entity
- Name
- American Council for International Studiesnorm: american council for international studies
Incident
- Discovered
- Jun 10, 2021
- Materiality determined
- —
- Notification sent
- Dec 3, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICMINOR
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this event to federal law enforcementNotified appropriate state regulators
Compliance
- Time to disclose
- 25 weeks(176 days from discovery to filing)
- Compliance flags
- CA 60-day late · 176d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 10, 2021→ Notified: Dec 3, 2021176d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.