Menu
Browse

Cyber Incident Victim: KEEN

Date:

Mar 2020

Location:

United States of America

Summary

Cybercriminals targeted a charitable shoe drive organized by KEEN during the coronavirus pandemic, resulting in the exposure of a dataset containing 183 million credentials, including Gmail users. The breach compromised personal information such as names, email and postal addresses, phone numbers, and account details, heightening phishing risks and broader security concerns for affected businesses.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Cybercriminals targeted KEEN’s charitable initiative during the COVID-19 pandemic, exploiting a shoe drive intended to assist individuals impacted by the global health crisis. The attack occurred amid heightened cybersecurity threats globally, with organizations like the UK National Cyber Security Centre attributing increased risks to expanded digital dependencies and ransomware activity during this period. While the exact date of the KEEN incident was not specified in available reports, its public documentation coincided with broader industry discussions about pandemic-related cybercrime trends in March 2020. No technical details regarding attack vectors, compromised systems, or data exfiltration were disclosed in the examined sources. The incident highlighted how threat actors leveraged humanitarian efforts during societal emergencies for potential financial gain or disruption.

Cyber Incident Image

Available records did not specify whether customer data, donor information, or operational systems were compromised during the attack on KEEN’s program. The lack of published technical indicators prevents confirmation of whether known vulnerabilities like CitrixBleed—actively exploited during this timeframe—or other flaws contributed to the breach. No mitigation actions, forensic investigations, or law enforcement responses specific to KEEN were detailed in the source material. The event occurred alongside multiple high-profile cybersecurity incidents during early 2020, including Microsoft’s emergency patches for zero-day exploits and SoundCloud’s breach affecting nearly 30 million accounts. This pattern underscored the elevated threat landscape facing organizations during pandemic-related operational shifts.

Sources
Sources available to members
1 source