MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
Polycystic Kidney Disease Foundation
bd_f7d100553c531787 · schema v1 · pii pii-v1
Full breach record for Polycystic Kidney Disease Foundation →The Polycystic Kidney Disease Foundation (PKDF) notified constituents of a data breach involving its CRM provider, Blackbaud. A ransomware attack on Blackbaud's service provider in May 2020 resulted in the exfiltration of a subset of PKDF data, including names, contact details, philanthropic interests, and transplant status. PKDF did not store SSNs or financial data. Blackbaud paid the ransom and assured data destruction. PKDF is notifying affected individuals and monitoring for misuse.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3c4211f7da1c5a0fOregon State AGfiled 2020-09-04Verified
- bd_aacdada4b0a038fdMontana State AGfiled 2020-09-04Verified
- bd_b57c6e4ad281bddeCalifornia State AGfiled 2020-09-04Verified
- bd_2e56f6d9b3a2f1baWashington State AGfiled 2020-09-03(1d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/10/PKD-Foundation-Data-Security-Breach-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2020
- Raw hash
- 635a991683d7cc23906f567d789264031d26f5d7a4c43d853168d294be54c0fd
Reporting entity
- Name
- Polycystic Kidney Disease Foundationnorm: polycystic kidney disease
- Domain
- pkdcure.org
Victim entity
- Name
- Polycystic Kidney Disease Foundationnorm: polycystic kidney disease
- Domain
- pkdcure.org
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Delaware Attorney General
- Third party
- via Blackbaud
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.