MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Kent Place School
bd_c1c555c3c7803805 · schema v1 · pii pii-v1
Full breach record for Kent Place School →Kent Place School notified the New Hampshire Attorney General of a security incident involving its vendor, Blackbaud. Blackbaud experienced a ransomware attack in May 2020, during which unauthorized access occurred between February 7 and May 20, 2020. Backup files containing names and Social Security numbers of 4 New Hampshire residents were exfiltrated. Kent Place School notified affected individuals on December 31, 2020, offering credit monitoring services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_069e6cecb3a2f9feMaine State AGfiled 2020-12-31(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kent-place-school-20210104.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 4, 2021
- Raw hash
- 2c2fe3b5d79658f3cab7ed8fa984faef3e0e0fc6498b4805f12386c16f507181
Reporting entity
- Name
- Kent Place Schoolnorm: kent place school
- Domain
- kentplace.org
Victim entity
- Name
- Kent Place Schoolnorm: kent place school
- Domain
- kentplace.org
Incident
- Discovered
- Sep 29, 2020
- Materiality determined
- —
- Notification sent
- Dec 31, 2020
- Affected individuals
- 4
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General Gordon MacDonald
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.