Skip to the content
Nairobi Tech Hub
  • HOME
  • Courses
  • Enroll
  • Jobs
  • About
  • Tech News
  • Contact
  • Login
  • HOME
  • Courses
  • Enroll
  • Jobs
  • About
  • Tech News
  • Contact
  • Login
Posted on March 10, 2023

SEC charges Blackbaud for failing to disclose ‘full impact’ of ransomware attack

  • By.
  • View Count. 0
  • 0 Comments

Software house Blackbaud has agreed to pay $3 million to settle charges related to a May 2020 ransomware attack that exposed customers’ bank account data, the U.S Security and Exchange Commission said on Thursday.

The SEC charged Blackbaud, whose cloud software is used by colleges, universities, nonprofits and far-right organizations, for making “misleading disclosures” about the cyberattack that affected more than 13,000 Blackbaud customers.

Although Blackbaud discovered the ransomware attack in May 2020, the company didn’t disclose the incident until  the following July. At the time, the South Carolina-based company told affected customers that only names, addresses, email addresses and telephone numbers had been stolen, asserting that “the cybercriminal did not access credit card information, bank account information, or Social Security numbers.”

But the SEC alleges that Blackbaud’s technology and customer relations personnel learned that the attacker had in fact accessed and exfiltrated this sensitive information “within days,” but did not tell senior managers responsible for public disclosure because the firm failed to maintain disclosure controls and procedures. Blackbaud didn’t admit that attackers had accessed customers’ bank account data and Social Security numbers until September in a filing with the SEC.

“As the order finds, Blackbaud failed to disclose the full impact of a ransomware attack despite its personnel learning that its earlier public statements about the attack were erroneous,” said David Hirsch, chief of the SEC enforcement division’s crypto assets and cyber unit. “Public companies have an obligation to provide their investors with accurate and timely material information; Blackbaud failed to do so.”

The Blackbaud ransomware attack impacted thousands of schools, universities and other non-profit organizations, including Des Moines University, Human Rights Watch, and the U.K.’s Labour Party. Blackbaud admitted that it paid a ransom to the hackers — a move discouraged by most law enforcement agencies — and claimed to have received “confirmation” that the attackers had destroyed the stolen personal data.

The SEC said on Thursday that, without admitting or denying the SEC’s findings, Blackbaud agreed to cease and desist from committing violations of these provisions and to pay a $3 million civil penalty.

Blackbaud didn’t respond to our questions.

Blackbaud’s cloud for ‘social good’ serves customers that work against human rights

SEC charges Blackbaud for failing to disclose ‘full impact’ of ransomware attack by Carly Page originally published on TechCrunch

Write a comment Cancel reply

This site uses User Verification plugin to reduce spam. See how your comment data is processed.

Quick Links

Home

About

Instructor Application

Privacy Policy

Terms of Service

Features

Courses

Tech News

FAQ

Contact

Contact

P.O Box 51722-00100 GPO Nairobi.
C/O Jacky Oreta

info@nairobitechhub.com

Follow Us on

Footer Logo
Ⓒ 2023 NairobiTechHub.

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.