Big Brothers Big Sisters
ent_a8f4e57d37435529cef0530c
Disclosures
8
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
35,072
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Big Brothers Big Sisters
- Normalized
- big brothers big sisters— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bigs.org
Disclosure history (8)newest first
- Massachusetts State AGas victim2023-11-27
Big Brothers Big Sisters of America reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-27. 1,230 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-11-22
Big Brothers Big Sisters of America (BBBSA) notified the Washington AG of a ransomware incident on or about March 28, 2023. The breach impacted approximately 15,604 Washington residents, exposing PII including SSNs, DOBs, driver's licenses, payment card data, and medical information. BBBSA engaged forensic investigators, notified the FBI, and began notifying affected individuals on November 22, 2023, offering credit monitoring.
- Delaware State AGas victim2023-11-22
Big Brothers Big Sisters of America (BBBSA) notified Delaware AG on November 22, 2023, regarding a cybersecurity incident occurring on March 28, 2023. An unauthorized actor accessed BBBSA's network and downloaded files containing personal information, including Social Security numbers and driver's license numbers. BBBSA notified the FBI, engaged external cybersecurity professionals, and is offering 12 months of credit monitoring and fraud assistance to affected individuals. The investigation was completed, and access was contained.
- Vermont State AGas victim2023-11-22
Big Brothers Big Sisters of America notified consumers of a data breach involving unauthorized access to personal information. Affected data included names, addresses, and Social Security numbers. The organization offered 12 months of credit monitoring and established a toll-free response line. The incident status is contained.
- Maine State AGas victim2023-11-22
Big Brothers Big Sisters of America ("BBBSA") reported an external system breach that occurred on March 28, 2023, and was discovered on November 15, 2023. The breach affected 123 Maine residents, compromising their names and financial account or credit/debit card numbers along with security codes or PINs. BBBSA began notifying affected individuals on November 22, 2023, and offered 12 months of credit monitoring and identity theft protection services through TransUnion's Identity Force.
- California State AGas victim2023-11-22
Big Brothers Big Sisters of America reported a data security breach affecting individuals across multiple US states, including California, New York, and Rhode Island. The incident involved unauthorized access to personal information, prompting the organization to offer 12 months of credit monitoring and establish a toll-free response line. Affected data likely included names and government identifiers.
- New Hampshire State AGas victim2023-11-22
Big Brothers Big Sisters of America notified the NH Attorney General of a security incident impacting its network on or about March 28, 2023. The organization contained the threat and engaged external cybersecurity professionals. Following a manual document review, it was determined on November 15, 2023, that personal information, including Social Security numbers, of approximately 35 New Hampshire residents was accessed or obtained. Notices were sent starting November 22, 2023. The investigation is ongoing.
- Montana State AGas victim2023-11-21
Big Brothers Big Sisters of America (BBBSA) reported a ransomware incident on March 28, 2023, attributed to the 'Royal' threat actor group. Unauthorized actors accessed and exfiltrated sensitive data including names, SSNs, driver's licenses, financial account details, credentials, and PHI. BBBSA paid a ransom to recover the data. 458 Montana consumers were affected. BBBSA engaged forensic experts, notified the FBI via IC3, and implemented extensive security enhancements including MFA, EDR, and enhanced training.