American Civil Liberties Union Foundation
ent_8e35b81ee17cce56791f7c2f
Disclosures
4
State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
86,269
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- American Civil Liberties Union Foundation
- Normalized
- american civil liberties union— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🍁Vermont State AGas victim2023-07-21
American Civil Liberties Union Foundation, Inc. notified Vermont AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC. Attackers exploited a vulnerability in MOVEit Transfer software to access donor data (names, DOB, SSN) on May 29-30, 2023. 575 individuals affected. PBI patched the vulnerability and offered 24 months of credit monitoring.
- ⛰️New Hampshire State AGas victim2023-07-19
ACLU Foundation notified NH AG of a breach involving third-party vendor Pension Benefit Information (PBI). PBI exploited a vulnerability in MOVEit Transfer software on May 29-30, 2023, exfiltrating PII of 575 donors/beneficiaries. ACLUF learned of the incident on June 22, 2023. Notifications sent July 21, 2023. 11 NH residents affected. PBI offered 24 months credit monitoring.
- 🦞Maine State AGas reporting2023-07-18
A subcontractor for the American Civil Liberties Union Foundation, Inc., Pension Benefit, LLC, was impacted by a data breach. The incident, described as an external system breach or hacking, compromised the names and Social Security numbers of 575 individuals, including 10 residents of Maine. The breach occurred on May 29, 2023, and was discovered on June 22, 2023. Affected individuals were notified on July 21, 2023, and offered 24 months of credit monitoring and identity theft protection services through Kroll.
- 🌲Washington State AGas victim2020-08-14
American Civil Liberties Union, Inc., a non-profit/charity sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2020-07-16 and filed notice on 2020-08-14. 86,269 Washington residents were affected. 29 days elapsed between awareness and notification. 160 days to identify the breach. 0 days to contain the breach.