Skip to content

Blackbaud

Disclosed Oct 7, 20205 years agoSettled

Official notice

2020 ransomware breach of donor data; FTC order, USD 3M SEC and USD 49.5M states

Attackers used a customer's credentials to enter Blackbaud's network in a ransomware attack it discovered in May 2020 and disclosed in July 2020,, stayed undetected over three months, and exfiltrated unencrypted data including Social Security and bank account numbers of millions of consumers. Blackbaud initially said such data was not taken; the FTC ordered it in 2024 to delete unneeded data and improve security.

What is known

People affectedNot stated in the sources we have
DisclosedOct 7, 2020
DiscoveredMay 2020
AttackRansomware
Data exposedNames, Addresses, Emails, Phone numbers, Social Security numbers, Financial
SectorTech · US
StatusSettled
Lawsuit or fineFTC consent order (Feb 2024); USD 3M SEC penalty (March 2023); USD 49.5M multistate AG settlement (Oct 2023) (about $53M)

Sources

Notices filed

WhereFiledPeople
ResearchtotalOct 7, 2020

Other breaches at Blackbaud

BreachAffected
Ransomware attack on donor software firm exposes nonprofit donor dataJul 16, 20206 years agoRansomwareUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Blackbaud

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.