HackingData ExfiltratedEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTHEALTH_BASICMediumContained
New York Blood Center Enterprises
bd_c5001b57e805910a · schema v1 · pii pii-v1
Full breach record for New York Blood Center Enterprises →New York Blood Center Enterprises experienced a cybersecurity incident between January 20 and January 26, 2025, where an unauthorized party accessed internal systems and exfiltrated files. Affected data included employee information (names, SSNs, government IDs, financial account details) and donor information (demographics, pre-screening questionnaires, infectious disease test results). The company secured systems, engaged forensic partners, and offered one year of identity monitoring to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_4cc7e1640f2d1cc8Maine State AGfiled 2025-09-05Candidate
- bd_55ee795695b6f651Delaware State AGfiled 2025-09-05Verified
- bd_69f70ca1ca2f3c49Oregon State AGfiled 2025-09-05Verified
- bd_8062973a873e99bfNew Hampshire State AGfiled 2025-09-05Verified
Show 4 more filings ↓Show fewer ↑up to 4d gap
- bd_8a44078c684109ddIndiana State AGfiled 2025-09-05Verified
- bd_98a5c223b0a3fe78Montana State AGfiled 2025-09-05Verified by operator
- bd_ef3dd2e5e9fec429Washington State AGfiled 2025-09-05Verified by operator
- bd_3c6450c461889c65Texas State AGfiled 2025-09-09(4d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-608189
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2025
- Raw hash
- 3c60dd7056b01fd036e89fc9c9879e2bb51f0a8e531961b85e0fcbf8318ece94
Reporting entity
- Name
- New York Blood Center Enterprisesnorm: new york blood center
Victim entity
- Name
- New York Blood Center Enterprisesnorm: new york blood center
Incident
- Discovered
- Jan 26, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 32 weeks(222 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.