Pennington Biomedical Research Foundation
bd_f1a1a20281040fe5 · schema v1 · pii pii-v1
Full breach record for Pennington Biomedical Research Foundation →Pennington Biomedical Research Foundation notified the NH Attorney General of a ransomware incident involving third-party vendor Blackbaud. An unauthorized individual accessed Blackbaud's systems between Feb 7 and May 20, 2020, obtaining backup copies of Pennington's accounting and donor databases. One NH resident's name and SSN were potentially compromised. Pennington notified the resident on Nov 10, 2020, and offered 12 months of identity monitoring. Pennington is reviewing its relationship with Blackbaud.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 7, 2020
Begins
Jul 16, 2020
Discovered
Nov 12, 2020
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_0f3bf50d227d71152020-09-28 · +45dVerified
- Indiana State AGbd_150cec2b7b8888502020-09-28 · +45dVerified
- Maine State AGbd_2413169b7c24c0892020-09-28 · +45dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 28 (MA), last Nov 12 (NH) — a 45-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.