Supply chain β›“ Supply Chain

Blackbaud CRM Ransomware/Data Theft (Nonprofits, Universities, Healthcare)

πŸ“… 2020-02-07 🏒 Blackbaud cloud CRM platform
Primary Source β†—

Incident Details

Blackbaud, the world’s largest provider of cloud software for nonprofits, universities, healthcare organizations, and foundations, disclosed in July 2020 that it had suffered a ransomware attack between February and May 2020. Before encrypting systems, the attackers exfiltrated donor and constituent data. Blackbaud paid the ransom and claimed to have received confirmation the data was destroyed β€” but initial disclosures downplayed the breach’s scope. In subsequent SEC filings, Blackbaud admitted the stolen data included Social Security numbers, bank account information, and credentials β€” contradicting their initial disclosures. The breach affected thousands of Blackbaud clients including hundreds of universities, healthcare organizations, charities, and nonprofits across the US, UK, Canada, and Australia. Notable affected organizations include University of California, Northwestern University, Rhode Island School of Design, 49ers Foundation, and numerous NHS trusts. In 2023, the FTC finalized a settlement with Blackbaud requiring comprehensive security improvements and prohibiting misleading security claims. Blackbaud also paid $3 million to the SEC for misleading disclosures about the breach scope, and $49.5 million to settle multistate attorney general investigations (49 states) β€” one of the largest AG multistate breach settlements.

Technical Details

Initial Attack Vector
Ransomware attackers infiltrated Blackbaud's self-hosted cloud environment; before deploying ransomware, exfiltrated a copy of a subset of data from its cloud backup environment; Blackbaud paid the ransom in exchange for assurance the data was deleted
Vendor / Product
Blackbaud cloud CRM platform
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2020-02-07 Breach occurred
  2. 2020-07-16 Publicly disclosed
  3. 2020-07-16 Customers notified