American Symphony Orchestra League
ent_b7cbdfd99903ee9321c2b8c7
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
49,063
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- American Symphony Orchestra League
- Normalized
- american symphony orchestra league— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- americanorchestras.org
Disclosure history (6)newest first
- Washington State AGas victim2020-10-09
American Symphony Orchestra League reported a ransomware attack on third-party vendor Blackbaud in May 2020. Attackers exfiltrated donor PII (names, addresses, donation history) before being expelled. Blackbaud paid ransom and confirmed data destruction. 1,355 Washington residents affected. Notifications sent in October 2020.
- Maine State AGas victim2020-10-05
American Symphony Orchestra League, a non-profit organization, reported a data breach affecting 49,063 individuals. The breach, described as an external system breach (hacking), occurred on May 1, 2020, and was discovered on August 1, 2020. Affected individuals were notified electronically on October 5, 2020.
- California State AGas victim2020-10-05
Blackbaud, a database vendor serving the League of American Orchestras (American Symphony Orchestra League), suffered a ransomware attack in which a cybercriminal removed a backup file containing donor/constituent personal information (names, addresses, phone numbers, email, demographic data, donation history). No credit card, bank account, or SSN data was involved. Blackbaud paid the ransom and obtained confirmation the data was destroyed. The letter was sent October 2020.
- Montana State AGas victim2020-10-05
League of American Orchestras notified Montana residents of a ransomware attack on third-party vendor Blackbaud. Attackers exfiltrated a backup file containing PII (names, addresses, donation history) before being expelled. Blackbaud paid the ransom and confirmed data destruction. No SSN or credit card data was accessed. Incident status is contained.
- Oregon State AGas victim2020-10-05
American Symphony Orchestra League reported a data breach to the Oregon Attorney General. The breach was reported on 2020-10-05. The breach occurred during 5/1/2020. The breach was discovered on 8/1/2020. 49,063 individuals were affected. Notice was sent on 10/5/2020.
- New Hampshire State AGas victim2020-10-02
American Symphony Orchestra League (dba League of American Orchestras) reported a third-party vendor breach involving Blackbaud. A ransomware attack in May 2020 led to exfiltration of donor data (names, addresses, phone, demographics, donation history) from 161 NH residents. Blackbaud paid ransom and confirmed data destruction. League notified donors and CRAs in Oct 2020.
Supply-chain cascadesreviewed and confirmed
- American Symphony Orchestra League’s filing is one of at least 172 in the BLACKBAUD, INC. supply-chain incident (2020).