MalwareRansomwareSupply Chain (3P Vendor)Data ExfiltratedData EncryptedRansom DemandedRansom PaidCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Georgia Southern University
bd_fefe1ef75864e294 · schema v1 · pii pii-v1
Full breach record for Georgia Southern University →Georgia Southern University reported a data breach involving its third-party vendor, Blackbaud. Between February 7 and May 20, 2020, unauthorized actors accessed backup files containing names, Social Security numbers, and donor profiles. The incident involved a ransomware attack where files were encrypted and a ransom was paid. The university notified affected individuals and provided one year of credit monitoring via Kroll. The university has since removed SSNs from the affected database and enhanced security controls.
California clockDiscovered Jul 16, 2020 → Notified Sep 8, 202054d ✓ CA 60-day OK12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a34a40eec8e52e7dMaine State AGfiled 2020-10-09Candidate
- bd_c85b3a4945e51a3fMaine State AGfiled 2020-11-13(35d gap)Verified
- bd_ff4ac37fb9490793Washington State AGfiled 2020-11-13(35d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194984
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2020
- Raw hash
- 442a85fdab172741935020e4e341589cd19a6a30a5fa426c096a67607c0cb029
Reporting entity
- Name
- Georgia Southern Universitynorm: georgia southern university
Victim entity
- Name
- Georgia Southern Universitynorm: georgia southern university
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- —
- Notification sent
- Sep 8, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 54d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 16, 2020→ Notified: Sep 8, 202054d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.