ResourcesTexas Breach Tracker › American Heart Association (Dallas HQ)
Healthcare Exfil Remediated

American Heart Association (Dallas HQ)
Breach Analysis

The American Heart Association — headquartered in Dallas, TX — disclosed a data breach affecting approximately 3 million donors. PII including donation history, contact information, and in some cases health-related data was exposed.

Incident Date
2023-09-12
Records Exposed
3,000,000
Attack Type
Exfil
Threat Actor
Unconfirmed

How they got in

Threat actor gained access to donor management database via compromised admin credentials. Extensive donor data — including health affinity indicators — exfiltrated over a period estimated at several weeks before detection.

Sentinel / Fortress / Command coverage

Sentinel Database query volume monitoring: bulk donor record export would trigger DLP alert within hours of exfiltration start
Sentinel Admin credential anomaly: non-routine bulk read queries from admin account — UEBA alert before significant data leaves the network
Fortress Credential compromise monitoring: admin password found in breach dataset prompts immediate rotation before threat actor uses it

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
TDPA Tex. B&C Code §521.053 Breach notification — 3M donors required notification; TX residents subset triggered AG notice
HIPAA 45 CFR §164.308(a)(3) Workforce access management — donor health affinity data accessible without appropriate controls

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.