DisclosureLens
MalwareOtherRansomwareData MishandlingSupply Chain (3P Vendor)Ransom DemandedRansom PaidData ExfiltratedCustomer Data InvolvedIdentity (basic)FinancialLowContained

American Symphony Orchestra League

bd_f76174bc00cc6235 · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 1, 2020

Filed

Oct 2, 2020

To disclose

9 weeks

Affected

161state residents only

Confidence

66%
Full breach record for American Symphony Orchestra League4 incidents on file

American Symphony Orchestra League (dba League of American Orchestras) reported a third-party vendor breach involving Blackbaud. A ransomware attack in May 2020 led to exfiltration of donor data (names, addresses, phone, demographics, donation history) from 161 NH residents. Blackbaud paid ransom and confirmed data destruction. League notified donors and CRAs in Oct 2020.

Incident timeline

undetected · 92 days
discovery → filing · 9 weeks / 62 days

May 1, 2020

Begins

Aug 1, 2020

Discovered

Oct 2, 2020

Filed

vs. sector median

+2 wks slower

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed161 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.