St. Sebastian's School suffered a data breach on May 1, 2020, stemming from a ransomware attack on its third-party vendor, Blackbaud, Inc. The incident exposed sensitive personal information, including Social Security numbers, of 1,721 individuals likely comprising students, staff, or associated parties. The breach was not detected until September 29, 2020, indicating a prolonged exposure window. While the attack targeted Blackbaud, St. Sebastian's School was indirectly impacted due to its reliance on the vendor’s compromised systems. The compromised data suggests a high-risk scenario involving identity theft, financial fraud, or long-term reputational harm for affected individuals. Blackbaud reportedly paid the ransom, but the delay in discovery and the nature of the stolen data (SSNs) amplify the severity of the incident. The breach underscores vulnerabilities in supply-chain cybersecurity and the cascading risks when vendors handling sensitive data are targeted.
TPRM report: https://www.rankiteo.com/company/saintsebastianschool
"id": "sai546082925",
"linkid": "saintsebastianschool",
"type": "Ransomware",
"date": "5/2020",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '1,721',
'industry': 'education',
'name': "St. Sebastian's School",
'type': 'educational institution'},
{'industry': 'technology/software',
'name': 'Blackbaud, Inc.',
'type': 'vendor (third-party)'}],
'data_breach': {'number_of_records_exposed': '1,721',
'personally_identifiable_information': ['Social Security '
'numbers'],
'sensitivity_of_data': 'high (SSNs)',
'type_of_data_compromised': ['personally identifiable '
'information (PII)']},
'date_detected': '2020-09-29',
'description': 'The Maine Office of the Attorney General reported that St. '
"Sebastian's School experienced a data breach on May 1, 2020, "
'due to a ransomware attack against its vendor, Blackbaud, '
'Inc. The breach affected 1,721 individuals, including '
'compromised Social Security numbers, and was discovered on '
'September 29, 2020.',
'impact': {'data_compromised': ['Social Security numbers'],
'identity_theft_risk': 'high (SSNs compromised)'},
'references': [{'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['Maine Office of the '
'Attorney General']},
'title': "St. Sebastian's School Data Breach via Blackbaud Ransomware Attack",
'type': 'data breach (ransomware)'}