MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedRansom PaidSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Archer School for Girls
bd_d4d793e1d76c3cc2 · schema v1 · pii pii-v1
Full breach record for Archer School for Girls →The Archer School for Girls reported a data breach involving its vendor, Blackbaud, Inc. Unauthorized access occurred between February 7, 2020, and May 20, 2020. The attacker exfiltrated backup files containing unencrypted personal information and attempted to encrypt files for ransom. Blackbaud paid the ransom and destroyed the stolen files. Archer notified affected individuals and offered two years of identity monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7b4f0aadc30a5b67Montana State AGfiled 2021-01-13Candidate
- bd_f2dd6311dc4bf5adMaine State AGfiled 2021-01-13Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198484
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 13, 2021
- Raw hash
- 8f4c42601e2cbfe8daa17fe3ff184eef61010e145dce2892f26ba742161ab14b
Reporting entity
- Name
- Archer School for Girlsnorm: archer school for girls
Victim entity
- Name
- Archer School for Girlsnorm: archer school for girls
Incident
- Discovered
- May 20, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 34 weeks(238 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.