DisclosureLens
MalwareOtherRansomwareRansom DemandedData ExfiltratedSupply Chain (3P Vendor)Multi-Stage ChainIdentity (basic)Financial accountLowActive

Direct Relief

bd_f1aced38a63e21be · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 16, 2020

Filed

Apr 28, 2021

To disclose

41 weeks

Affected

926state residents only

Confidence

69%
Full breach record for Direct Relief

Direct Relief notified the Washington AG of a third-party breach involving Blackbaud. A threat actor exfiltrated data from Blackbaud's systems between Feb 7 and May 20, 2020, and attempted a ransomware attack on May 20. Direct Relief was notified by Blackbaud on July 16, 2020. Data potentially included names, DOBs, and financial account numbers for 926 Washington residents. Direct Relief engaged forensic experts and is notifying affected individuals.

Incident timeline

undetected · 160 days
discovery → filing · 41 weeks / 286 days

Feb 7, 2020

Begins

Jul 16, 2020

Discovered

Apr 28, 2021

Filed

vs. sector median

+33 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed926 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.