Blood Systems, Inc.
bd_e43660f889345f7d · schema v1 · pii pii-v1
Full breach record for Blood Systems, Inc. →Blood Systems, Inc. detected unauthorized access to its eDonor donor portal on Sept. 4, 2018. Investigation revealed that between Aug. 29 and Sept. 2, 2018, a small number of donor profiles were accessed. Attackers fraudulently used loyalty points to order gift cards. Affected data included name, DOB, blood type, contact info, appointment history, donation history, and wellness metrics (vitals). No SSNs or financial account records were involved. The company disabled logins, reset passwords with enhanced security, restored points, and worked with vendor Haemonetics Software Solutions to investigate and upgrade security.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 29, 2018
Begins
Sep 4, 2018
Discovered
Sep 20, 2018
Filed
vs. sector median
10 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.