More than 20 universities and charities in the UK, US, and Canada had confirmed they are victims of a cyber-attack that compromised a software supplier.
Dozens more charities and educational organizations had been affected and the Vermont Foodbank is among them.
Compromised information included personal details that were limited to those of former students, who had been asked to financially support the establishments from which they had graduated. It also extended to staff, existing students, and other supporters.
Compromised data also included the stolen data including phone numbers, donation history and events attended.
Source: https://www.bbc.com/news/technology-53528329
TPRM report: https://scoringcyber.rankiteo.com/company/vermont-foodbank
"id": "ver11415123",
"linkid": "vermont-foodbank",
"type": "Breach",
"date": "05/2020",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Non-profit',
'location': 'Vermont, USA',
'name': 'Vermont Foodbank',
'type': 'Charity'}],
'attack_vector': 'Compromised Software Supplier',
'data_breach': {'type_of_data_compromised': ['Personal details',
'Phone numbers',
'Donation history',
'Events attended']},
'description': 'More than 20 universities and charities in the UK, US, and '
'Canada had confirmed they are victims of a cyber-attack that '
'compromised a software supplier. Dozens more charities and '
'educational organizations had been affected and the Vermont '
'Foodbank is among them. Compromised information included '
'personal details that were limited to those of former '
'students, who had been asked to financially support the '
'establishments from which they had graduated. It also '
'extended to staff, existing students, and other supporters. '
'Compromised data also included the stolen data including '
'phone numbers, donation history and events attended.',
'impact': {'data_compromised': ['Personal details',
'Phone numbers',
'Donation history',
'Events attended']},
'title': 'Cyber Attack on Universities and Charities',
'type': 'Data Breach'}