DisclosureLens
MalwareEducationEducationRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)TargetedIdentity (basic)Financial accountMediumContained

Tidewater Community College Education Foundation

bd_fb66cd1d6114f655 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 1, 2020

Filed

Sep 17, 2020

To disclose

20 weeks

Affected

1,029state residents only

Confidence

69%
Full breach record for Tidewater Community College Education Foundation

Tidewater Community College Education Foundation (TCCEF) notified the Washington AG of a ransomware attack on its third-party cloud provider, Blackbaud. The incident occurred between Feb 7 and May 20, 2020. Blackbaud discovered the attack in May 2020. Data potentially accessed included names, addresses, DOBs, and partial credit card info for 1,029 WA residents. TCCEF notified residents via email.

Washington clock WA AG >90d20 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 84 days
discovery → filing · 20 weeks / 139 days

Feb 7, 2020

Begins

May 1, 2020

Discovered

Sep 17, 2020

Filed

vs. sector median

+13 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,029 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.