"

Estimated reading time: 1 minute, 42 seconds

SEC Whacks Blackbaud for $3 Million

Ransomware lock The SEC’s finding Blackbaud made misleading statements about a 2020 ransomware attack has led to the company agreeing to a $3-million civil penalty. The company also agreed to cease and desist from violations of the Securities Act of 1933, the agency said this week.'s

On July 16, 2020, the non-profit software company announced “the ransomware attacker did not access donor bank account information or Social Security numbers,” according to the SEC statement. In fact, the attackers accessed unencrypted customer information.

The SEC said the event affected more than 13,000 of the nonprofit software company’s customers, which the agency described as a quarter of Blackbaud’s customers. Blackbaud said records of roughly  6 million individuals were involved. Last year, Blackbaud said the intrusion would cost it $25 million to $35 million.

While Blackbaud determined within days of the announcements that records had been accessed the company’s technology and customer relations personnel did not communicate this information to senior management “because the company failed to maintain disclosure controls and procedures,” according to the SEC.

Blackbaud received more than 1,000 customer inquiries about the attack with some concerned they had uploaded sensitive data to fields that were not encrypted. A few days later, company service personnel used a Blackbaud script that acknowledged the fields were unencrypted.

Blackbaud faces several lawsuits over the attack.

Bob Scott
Bob Scott has provided information to the tax and accounting community since 1991, first as technology editor of Accounting Today, and from 1997 through 2009 as editor of its sister publication, Accounting Technology. He is known throughout the industry for his depth of knowledge and for his high journalistic standards.  Scott has made frequent appearances as a speaker, moderator and panelist and events serving tax and accounting professionals. He  has a strong background in computer journalism as an editor with two former trade publications, Computer+Software News and MIS Week and spent several years with weekly and daily newspapers in Morris County New Jersey prior to that.  A graduate of Indiana University with a degree in journalism, Bob is a native of Madison, Ind
Read 1334 times
Rate this item
(0 votes)

Visit other PMG Sites:

Template Settings

Color

For each color, the params below will give default values
Tomato Green Blue Cyan Dark_Red Dark_Blue

Body

Background Color
Text Color

Header

Background Color

Footer

Select menu
Google Font
Body Font-size
Body Font-family
Direction
PMG360 is committed to protecting the privacy of the personal data we collect from our subscribers/agents/customers/exhibitors and sponsors. On May 25th, the European's GDPR policy will be enforced. Nothing is changing about your current settings or how your information is processed, however, we have made a few changes. We have updated our Privacy Policy and Cookie Policy to make it easier for you to understand what information we collect, how and why we collect it.