DisclosureLens
MalwareGovernmentGovernmentRansomwareRansom DemandedRansom PaidData ExfiltratedSupply Chain (3P Vendor)Government IDFinancial accountIdentity (basic)HighContained

Thrive Upstate

bd_d93a7c4a7b8e4125 · schema v1 · pii pii-v1

Severity

High

Discovered

Oct 30, 2020

Filed

Dec 28, 2020

To disclose

8 weeks

Affected

2,700state residents only

Confidence

65%
Full breach record for Thrive Upstate →

Thrive Upstate notified South Carolina residents of a ransomware attack on third-party provider BlackBaud, Inc. in 2020. The attacker exfiltrated a backup file containing names, SSNs, addresses, and bank account information before being expelled. Thrive Upstate paid the ransom and provided 24 months of credit monitoring and fraud resolution services to affected individuals.

South Carolina clock✓ SC CRA notice due8 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

discovery → filing · 8 weeks / 59 days

Oct 30, 2020

Discovered

Dec 28, 2020

Filed

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,700 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.