🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme

Blackbaud exposed your personal health information and basically got away with it

Blackbaud’s Billion-Dollar Betrayal: Data Fumbled, Public Deceived

An Unlocked Digital Vault

Blackbaud, Inc. is a massive corporation, managing the sensitive data of over 45,000 nonprofits, hospitals, and universities. On February 7, 2020, an attacker used a customer’s login credentials to walk into their digital fortress. According to the Federal Trade Commission (FTC) complaint (Docket No. C-4804), that attacker remained inside, undetected, for over three months.

It was not until May 20, 2020, that an engineering team member noticed a suspicious login. By then, it was too late. The intruder had moved freely across Blackbaud’s networks, exploiting existing vulnerabilities to create their own administrator accounts and siphon off massive amounts of data belonging to tens of thousands of Blackbaud’s customers.

The Non-Financial Ledger: Your Life, Unencrypted

The scale of the company’s negligence is staggering. The data stolen was not just names and emails. Blackbaud’s “deficient encryption practices” meant the attacker exfiltrated a complete digital profile of millions of people, all of it unencrypted and unprotected.

The stolen files included: Social Security numbers, bank account information, estimated wealth, home addresses, phone numbers, medical record identifiers, treating physician names, health insurance information, reasons for seeking medical treatment, religious beliefs, marital status, and employment information, including salaries. They even hoarded data from former customers for years longer than necessary, expanding the blast radius of their failure.

This is the non-financial ledger of the damage. It is a permanent record of betrayal, where the most intimate details of a person’s health, faith, and finances were treated as disposable and left wide open for theft.

Legal Receipts: Their Own Words, Our Evidence

After paying the hacker a ransom of 24 Bitcoin (valued at $235,000 at the time) for a promise to delete the data—a promise they admit they cannot verify—Blackbaud finally notified its customers on July 16, 2020. That notification was a calculated deception.

The FTC complaint reveals this was a lie. By July 31, 2020, Blackbaud’s own investigation confirmed that the attacker *had* stolen bank account numbers and Social Security numbers. The company sat on this information, leaving millions of people vulnerable, and did not issue a correction until October 2020.

This deception was layered on top of another one. The company’s own privacy policy claimed it maintained “appropriate physical, electronic and procedural safeguards.” The FTC found this to be false, citing a laundry list of failures including weak passwords, no multifactor authentication, and a failure to monitor its own networks for data theft.

Societal Impact Mapping

Public Health & Dignity

The theft of medical data is a profound violation. It exposes people to potential discrimination, blackmail, and severe emotional distress. Information about why you sought treatment or who your doctor is belongs to you. Blackbaud’s negligence turned that private trust into a commodity for cybercriminals.

Economic Inequality

The harm from this breach falls directly on working people. While a billion-dollar company negotiated a settlement with regulators, its customers and their donors were left to deal with the fallout. The FTC notes that since the breach, Blackbaud received multiple complaints involving attempted identity theft and fraud using the stolen information, including credit card, tax, and unemployment scams. The cost of credit monitoring, frozen accounts, and stolen identities is paid by the victims, not the corporation that failed them.

$235,000
The Ransom Blackbaud Paid to Make the Problem ‘Disappear’
VS.
Millions
Consumers Whose Most Sensitive Data Was Exposed Forever

What Now? A Watchlist For The Powerless

The FTC’s “Decision and Order” against Blackbaud contains no financial penalty. The corporation was ordered to delete the data it should have already deleted and implement a comprehensive security program—the kind of program it should have had in the first place. Blackbaud neither admits nor denies the allegations.

This is not justice. It is a business-as-usual compliance agreement that forces no real accountability for the harm caused. Since the system will not hold them accountable, we must.

Corporate Roles to Watch

  • The Chief Executive Officer
  • The Chief Information Security Officer
  • The Board of Directors

Regulatory Watchlist

  • Federal Trade Commission (FTC): This agency had the power to levy significant fines and chose instead to issue a procedural slap on the wrist. They are a watchdog with no teeth when it comes to penalizing corporate negligence that harms millions.

The Resistance

Waiting for regulators to protect you is a failing strategy. True power comes from the ground up. Support mutual aid funds that help victims of identity theft recover. Demand local and federal representatives pass data privacy laws with mandatory, multi-million dollar fines for this level of negligence. A company that makes a billion dollars a year will only change its behavior when the cost of failure outweighs the cost of compliance.

The source document for this investigation is attached below.


Please read me: https://www.ftc.gov/system/files/ftc_gov/pdf/2023181_blackbaud_final_consent_package.pdf

📢 Explore Corporate Misconduct by Category

🚨 Every day, corporations engage in harmful practices that affect workers, consumers, and the environment. Browse key topics:

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 1826