Tzu Chi Foundation
ent_d194992a7cb26e6bed0a9100
Disclosures
5
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
15,838
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Tzu Chi Foundation
- Normalized
- tzu chi— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- global.tzuchi.org
Disclosure history (5)newest first
- Massachusetts State AGas victim2021-10-18
Buddhist Tzu Chi Foundation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-10-18. 159 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-10-18
Buddhist Tzu Chi Foundation discovered on July 15, 2021, that several computers were operating unusually and portions of their network were inaccessible. The organization took systems offline and investigated. Personal information including name, address, phone, email, date of birth, and emergency contact may have been present on affected systems. It is unknown if data was accessed or removed. Workstation security software was upgraded.
- Indiana State AGas victim2021-10-06
Buddhist Tzu Chi Education Foundation reported a data breach to the Indiana Attorney General. 9 Indiana residents were affected. 15,838 individuals affected in total.
- California State AGas victim2021-10-06
Buddhist Tzu Chi Education Foundation discovered unusual computer activity and network inaccessibility on July 15, 2021. The incident potentially exposed personal information including names, addresses, passport numbers, driver's license numbers, and Social Security Numbers. The organization took systems offline and upgraded security software. No specific attack vector or threat actor was identified.
- California State AGas reporting2021-08-02
Buddhist Tzu Chi Foundation disclosed a ransomware attack discovered on July 15, 2021. The incident compromised systems containing private and confidential information, including Social Security Numbers, driver's license numbers, financial information, and medical/health insurance information. The organization engaged law enforcement and third-party specialists, reviewed network security policies, and offered credit monitoring services to impacted staff, volunteers, vendors, and clients.