CSIDB logo
Incident

American Museum of Natural History

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
American Museum of Natural History
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers accessed personal information of visitors at the American Museum of Natural History, compromising contact details, demographic data, and donation histories. The breach occurred through a third-party system operated by Blackbaud, though financial information such as credit card or bank account data remained unaffected. The involved company stated no evidence suggested the stolen data was further disseminated and engaged external security monitoring to detect potential disclosures.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The American Museum of Natural History disclosed a data breach in October 2020 involving unauthorized access to visitor information by hackers. The incident occurred between February and May 2020, affecting systems managed by the museum's third-party service provider Blackbaud. Compromised data included visitor contact information, demographic details, and records of prior donations to the institution. Financial data such as credit card numbers or bank account information remained unaffected according to the museum's assessment. The breach was detected and contained by Blackbaud, though specific details about the discovery method or intrusion vectors were not publicly disclosed.

Blackbaud confirmed the breach impacted multiple organizations beyond the museum and stated there was no evidence the stolen data had been disseminated or misused following the incident. The company engaged a third-party cybersecurity firm to monitor dark web channels for any signs of the compromised information appearing for sale or distribution. The museum notified affected individuals about the breach but did not specify the total number of impacted visitors or donors. No ransomware demands or public extortion attempts related to this specific breach were reported by either the museum or Blackbaud. The institution maintained operations throughout the incident period with no reported disruptions to public services or exhibitions.

Sources

Sources available to members: 1 source.

CSIDB