DisclosureLens
MalwareEducationEducationRansomwareRansom DemandedRansom PaidData ExfiltratedSupply Chain (3P Vendor)Identity (basic)LowResolved

The University of South Carolina Upstate Foundations

bd_be237c0c42542cb7 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 1, 2020

Filed

Sep 14, 2020

To disclose

19 weeks

Affected

3state residents only

Linked

3 filings

Confidence

63%
Full breach record for The University of South Carolina Upstate Foundations2 incidents on file

The University of South Carolina Upstate Foundations notified individuals of a ransomware attack on third-party vendor Blackbaud's platform. The incident occurred between Feb 7 and May 20, 2020. Affected data included names, addresses, and other personal info. The vendor paid the ransom and confirmed data destruction. The University offered one year of credit monitoring.

Incident timeline

undetected · 84 days
discovery → filing · 19 weeks / 136 days

Feb 7, 2020

Begins

May 1, 2020

Discovered

Sep 14, 2020

Filed

vs. sector median

+12 wks slower

This filing is one of 3 about the same incident.View merged incident
Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Maine State AGSep 14 · first
Montana State AGSep 14 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.