MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Vermont Student Assistance Corporation
bd_bca2d0e8282fb4bc · schema v1 · pii pii-v1
Full breach record for Vermont Student Assistance Corporation →Vermont Student Assistance Corporation (VSAC) notified California AG of a breach involving its third-party vendor, Blackbaud, Inc. A ransomware attack on Blackbaud in May 2020 resulted in the encryption of systems and unauthorized removal of a VSAC database backup containing names and Social Security numbers between Feb 7 and May 20, 2020. VSAC offered 12 months of credit monitoring via Experian.
California clockDiscovered Jul 16, 2020 → Notified Sep 4, 202050d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_08c27a98ee1b1bf4California State AGfiled 2020-09-25(21d gap)Verified
- bd_2c1946e3a02b4317Maine State AGfiled 2020-09-25(21d gap)Candidate
- bd_79f77c4712b37181Montana State AGfiled 2020-10-04(30d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193789
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2020
- Raw hash
- d3384110daee8013692f02b408dc9864700ecf3db0a66b423c182e3258452f6e
Reporting entity
- Name
- Vermont Student Assistance Corporationnorm: vermont student assistance
Victim entity
- Name
- Vermont Student Assistance Corporationnorm: vermont student assistance
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- Sep 4, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying state and federal regulators
- Third party
- via Blackbaud, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 50d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 16, 2020→ Notified: Sep 4, 202050d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.