Special Olympics Wisconsin, Inc.

Special Olympics Wisconsin, Inc.

Special Olympics Wisconsin, Inc. suffered a data breach due to a cybersecurity incident at its third-party software provider, Blackbaud, Inc. The breach occurred between February 7, 2020, and May 20, 2020, where unauthorized actors accessed and exfiltrated backup files. The compromised data included sensitive personal information such as names, driver’s license numbers, and dates of birth of 23,724 individuals, with at least 2 Maine residents officially notified on October 30, 2020. The incident stemmed from an external system breach at Blackbaud, highlighting vulnerabilities in third-party vendor security. While the exact method of exploitation (e.g., phishing, unpatched software) was not detailed, the exposure of personally identifiable information (PII) poses risks of identity theft, fraud, or targeted scams. The breach did not involve ransomware or direct financial theft but resulted in the unauthorized removal of sensitive data, impacting both participants and stakeholders associated with the organization. The delayed notification (over 5 months after discovery) further underscores challenges in breach response coordination between affected entities and third-party vendors. The incident emphasizes the critical need for robust vendor risk management and proactive monitoring to mitigate supply-chain cyber threats.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c4a7b78b-ab70-4587-b33f-61a85393a6ab.shtml

TPRM report: https://www.rankiteo.com/company/special-olympics

"id": "spe004091825",
"linkid": "special-olympics",
"type": "Breach",
"date": "2/2020",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 23724,
                        'industry': 'Sports/Disability Services',
                        'location': 'Wisconsin, USA',
                        'name': 'Special Olympics Wisconsin, Inc.',
                        'type': 'Non-profit Organization'},
                       {'industry': 'Technology/Cloud Services',
                        'name': 'Blackbaud, Inc.',
                        'type': 'Software Provider'}],
 'customer_advisories': 'Notification sent to affected individuals (including '
                        '2 Maine residents on October 30, 2020)',
 'data_breach': {'data_exfiltration': 'Yes (unauthorized removal of backup '
                                      'files)',
                 'file_types_exposed': ['Backup files'],
                 'number_of_records_exposed': 23724,
                 'personally_identifiable_information': ['Names',
                                                         "Driver's license "
                                                         'numbers',
                                                         'Dates of birth'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personal Identifiable '
                                              'Information (PII)']},
 'date_publicly_disclosed': '2020-10-30',
 'description': 'The Maine Office of the Attorney General reported that '
                'Special Olympics Wisconsin, Inc. experienced a data breach '
                'involving its software provider, Blackbaud, Inc., due to an '
                'external system breach that occurred between February 7, '
                '2020, and May 20, 2020. The breach involved the unauthorized '
                "removal of backup files containing individuals' names, "
                "driver's license numbers, and/or dates of birth, affecting a "
                'total of 23,724 individuals, with 2 residents of Maine '
                'notified on October 30, 2020.',
 'impact': {'data_compromised': ['Names',
                                 "Driver's license numbers",
                                 'Dates of birth'],
            'identity_theft_risk': 'High (PII exposed)'},
 'references': [{'source': 'Maine Office of the Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
                                                       'Attorney General'},
 'response': {'communication_strategy': 'Notification to affected individuals '
                                        '(e.g., 2 Maine residents notified on '
                                        'October 30, 2020)'},
 'title': 'Data Breach at Special Olympics Wisconsin via Blackbaud, Inc.',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.