
In a landmark agreement, the attorneys general of 49 states and Washington, D.C., have reached a substantial $49.5 million settlement with software company Blackbaud over a significant 2020 data breach that compromised the sensitive information of millions of individuals.
Blackbaud, a software provider serving nonprofits, including charities, schools, and healthcare agencies, disclosed a ransomware attack in July 2020, which resulted in the theft of extensive data, including demographic information, Social Security numbers, driver’s license numbers, financial records, employment and wealth data, donation histories, and protected health information.
This cyberattack exposed the information of over 13,000 Blackbaud’s business clients and millions of downstream users. The company faced legal action from attorney generals from all states except California, citing violations of state consumer protection laws, breach-notification laws, and the federal Health Insurance Portability and Accountability Act (HIPAA). The lawsuit accused Blackbaud of failing to implement adequate data security measures and address fundamental security vulnerabilities. It asserted that unauthorized individuals had gained access to Blackbaud’s network and that the company failed to promptly, fully, or accurately inform its customers about the breach, as mandated by law.
The lawsuit highlighted that Blackbaud’s actions significantly delayed notifying those affected, and in some cases, there was no notification at all. As a result of this settlement, each state involved will receive a portion of the $49.5 million, with Ohio Attorney General Dave Yost securing $1.3 million for Ohio. Yost emphasized that negligence cannot justify compromising consumer data, emphasizing the importance of companies committing to safeguarding personal information and meeting consumers’ expectations of data privacy and protection.
Notably, on July 16, 2020, Blackbaud stated that ransomware attackers had not accessed donor bank account information or Social Security numbers. However, this assertion was later found to be false. Alarmingly, the company’s IT staff did not inform senior management of the error for several days, and Blackbaud did not disclose this information in its subsequent quarterly report to the SEC the following month. In March, the company reached a $3 million settlement with the Securities and Exchange Commission regarding the incident.
In addition to the monetary settlement, Blackbaud is now obligated to take various corrective actions, including explaining its handling of customer data, implementing a data breach response plan, establishing a mechanism to assist customers in case of a breach, reporting all incidents to the company’s CEO and board, providing employee cybersecurity training, enhancing safeguards for personal information handling, implementing network segmentation, patch management systems, and permitting third-party compliance testing for seven years.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543