March of Dimes
bd_de337a6970bcfbd0 · schema v1 · pii pii-v1
Full breach record for March of Dimes →March of Dimes Inc. filed a supplemental notice with the Washington AG regarding a ransomware attack on its third-party vendor, Blackbaud, Inc. The incident, occurring between Feb-May 2020, exposed donor PII (names, addresses, DOB) and limited PHI (health conditions). 446,097 Washington residents were affected. Blackbaud paid ransom, confirmed data destruction, and continues monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 7, 2020
Begins
Jul 16, 2020
Discovered
Aug 14, 2020
Filed
vs. sector median
4 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.