MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Florida Gulf Coast University Foundation, Inc.
bd_c8c97bc3e0887fba · schema v1 · pii pii-v1
Full breach record for Florida Gulf Coast University Foundation, Inc. →Florida Gulf Coast University Foundation, Inc. reported a ransomware incident involving its vendor, Blackbaud, occurring between May 14 and May 20, 2020. The breach was discovered on December 5, 2020, affecting 5,489 individuals, including 26 Maine residents. Personal information and financial account numbers were compromised. The Foundation provided 12 months of credit monitoring and identity restoration services through TransUnion to affected individuals.
Maine clockDiscovered Dec 5, 2020 → Filed with AG Jan 4, 202130d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c123755c7024cff3Montana State AGfiled 2021-01-04Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/20c4dfca-80c9-4b4b-a5f5-611a8c6d1328.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 4, 2021
- Raw hash
- f82e684eac845bab641f414ce7603514be54204085c68dcea71c2bf7a4ca2929
Reporting entity
- Name
- Florida Gulf Coast University Foundation, Inc.norm: florida gulf coast university
- Domain
- fgcu.edu
Victim entity
- Name
- Florida Gulf Coast University Foundation, Inc.norm: florida gulf coast university
- Domain
- fgcu.edu
Incident
- Discovered
- Dec 5, 2020
- Materiality determined
- —
- Notification sent
- Jan 4, 2021
- Affected individuals
- 5,489
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 5, 2020→ Filed with AG: Jan 4, 202130d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.