Blackbaud to Pay $3M Fine for 'Misleading' Customers Following 2020 Ransomware Attack, Data Breach

Blackbaud, a South Carolina-based provider of administrative, donor management, and CRM software to thousands of K–12 private schools, higher education institutions, and nonprofits, has been ordered by the U.S. Securities and Exchange Commission to pay a fine of $3 million to “settle charges for making misleading disclosures about a 2020 ransomware attack that impacted more than 13,000 customers,” the federal agency said in a news release.

The SEC order said that during the ransomware attack, bank account information and Social Security numbers of donors stored by Blackbaud customers were stolen by the attackers, but Blackbaud had told customers the opposite and subsequently omitted the information in quarterly filings with the SEC. 

“On July 16, 2020, Blackbaud announced that the ransomware attacker did not access donor bank account information or Social Security numbers. Within days of these statements, however, the company’s technology and customer relations personnel learned that the attacker had in fact accessed and exfiltrated this sensitive information,” said the SEC order. “These employees did not communicate this information to senior management responsible for its public disclosure because the company failed to maintain disclosure controls and procedures.” 

In its August 2020 quarterly report filed with the SEC, Blackbaud “omitted this material information about the scope of the attack and misleadingly characterized the risk of an attacker obtaining such sensitive donor information as hypothetical,” the agency said.

“Public companies have an obligation to provide their investors with accurate and timely material information; Blackbaud failed to do so,” said David Hirsch, chief of the SEC Enforcement Division’s Crypto Assets and Cyber Unit. 

The agency ruled that Blackbaud violated two sections of the Securities Act of 1933 and one section of the Securities Exchange Act of 1934 as well as Rules 12b-20, 13a-13, and 13a-15(a). 

“Without admitting or denying the SEC’s findings, Blackbaud agreed to cease and desist from committing violations of these provisions” and to pay the fine of $3 million, the agency said.

According to its website, Blackbaud provides cloud-based software for education and nonprofit fundraising and donor relationship management, enrollment, finance, grants and awards, and marketing management. 

Its education customer base includes “24 of 25 top private U.S. colleges as ranked by Forbes,” the Blackbaud website says, and its software powers “93% of higher education institutions with billion-dollar campaigns.” Major universities using its donor management and CRM software include University of Georgia, Notre Dame, University of Louisville, and California State University Long Beach, according to Blackbaud.com.

 

 

About the Author

Kristal Kuykendall is editor, 1105 Media Education Group. She can be reached at [email protected].


Featured

  • businessmen shaking hands behind digital technology imagery

    Microsoft, OpenAI Restructure AI Partnership

    Microsoft and OpenAI announced they are redefining their partnership as part of a major recapitalization effort aimed at preparing for the arrival of artificial general intelligence (AGI).

  • stylized figures, resumes, a graduation cap, and a laptop interconnected with geometric shapes

    OpenAI to Launch AI-Powered Jobs Platform

    OpenAI announced it will launch an AI-powered hiring platform by mid-2026, directly competing with LinkedIn and Indeed in the professional networking and recruitment space. The company announced the initiative alongside an expanded certification program designed to verify AI skills for job seekers.

  • abstract metallic cubes and networking lines

    Call for Speakers Now Open for Tech Tactics in Education: Roadmap to AI Impact

    The virtual conference from the producers of Campus Technology and THE Journal will return on May 13, 2025, with a focus on emerging trends in with a focus on emerging trends in AI, cybersecurity, data, and ed tech.

  • padlock and circuit patterns

    Veeam to Acquire Securiti AI to Combine Data Resilience and AI Security

    Veeam Software has announced plans to acquire Securiti AI for $1.725 billion to unite data resilience, privacy, and AI trust in a platform aimed at helping organizations securely manage and unlock the value of their data across hybrid and multi-cloud environments.