Blackbaud Fined $3M for 'Failing to Disclose' That Ransomware Attack Breached Private Data

Blackbaud, a South Carolina-based provider of administrative, donor management, and CRM software to education and nonprofit organizations, has been fined $3 million by the U.S. Securities and Exchange Commission "for making misleading disclosures about a 2020 ransomware attack that impacted more than 13,000 customers,” the federal agency said. 

The SEC order said that during the ransomware attack, bank account information and Social Security numbers of donors stored by Blackbaud customers were stolen by the attackers, but Blackbaud had told customers the opposite and subsequently omitted the information in quarterly filings with the SEC. 

“On July 16, 2020, Blackbaud announced that the ransomware attacker did not access donor bank account information or Social Security numbers. Within days of these statements, however, the company’s technology and customer relations personnel learned that the attacker had in fact accessed and exfiltrated this sensitive information,” said the SEC order. “These employees did not communicate this information to senior management responsible for its public disclosure because the company failed to maintain disclosure controls and procedures.” 

In its August 2020 quarterly report filed with the SEC, Blackbaud “omitted this material information about the scope of the attack and misleadingly characterized the risk of an attacker obtaining such sensitive donor information as hypothetical,” the agency said.

“Public companies have an obligation to provide their investors with accurate and timely material information; Blackbaud failed to do so,” said David Hirsch, chief of the SEC Enforcement Division’s Crypto Assets and Cyber Unit. 

The agency ruled that Blackbaud violated two sections of the Securities Act of 1933 and one section of the Securities Exchange Act of 1934 as well as Rules 12b-20, 13a-13, and 13a-15(a). 

“Without admitting or denying the SEC’s findings, Blackbaud agreed to cease and desist from committing violations of these provisions” and to pay the fine of $3 million, the agency said.

According to its website, Blackbaud provides cloud-based software for education and nonprofit fundraising and donor relationship management, enrollment, finance, grants and awards, and marketing management.

 

 

About the Author

Kristal Kuykendall is editor, 1105 Media Education Group. She can be reached at [email protected].


Featured

  • magnifying glass with AI icon in the center

    Google Releases Learning-Themed AI Mode Features for Search

    Ahead of back-to-school season, Google has introduced new AI Mode features in Search, including image and PDF queries on desktop, a Canvas tool for planning, real-time help with Search Live, and Lens integration in Chrome.

  • abstract pattern of cybersecurity, ai and cloud imagery

    Report Identifies Malicious Use of AI in Cloud-Based Cyber Threats

    A recent report from OpenAI identifies the misuse of artificial intelligence in cybercrime, social engineering, and influence operations, particularly those targeting or operating through cloud infrastructure. In "Disrupting Malicious Uses of AI: June 2025," the company outlines how threat actors are weaponizing large language models for malicious ends — and how OpenAI is pushing back.

  • laptop displaying a phishing email icon inside a browser window on the screen

    ED Grant Portal Target of Phishing Campaign

    Threat researchers at BforeAI have identified a phishing campaign spoofing the U.S. Department of Education's G5 grant management portal.

  • laptop displaying AI-powered educational content

    Kira Introduces AI-Generated Lesson Tool

    AI company Kira has announced a new AI-powered lesson generation tool that it says delivers complete, standards-aligned lessons that are personalized to each student.