Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor management — disclosed that it had been hit by ransomware in May. It said it had paid the attackers in exchange for confirmation that stolen data had been destroyed.
What happened
Attackers accessed Blackbaud's systems, attempted to encrypt them and copied a subset of customer data. Blackbaud said it stopped the encryption and paid the ransom. Thousands of its customers — charities, schools, hospitals — then had to notify donors, students and patients that their data had been exposed through a vendor.
Why it mattered
- Third-party ransomware becomes your breach. Blackbaud's customers bore notification costs and reputational damage for an incident they didn't control.
- "Paid to delete" offers little assurance. Security experts and regulators questioned whether payment guaranteed deletion.
- Disclosure accuracy matters. In 2023, the US Securities and Exchange Commission charged Blackbaud with making misleading disclosures about the incident's scope, and the company agreed to a penalty. The FTC and state attorneys general also took action.
Lessons for organizations using SaaS
- Know which vendors hold sensitive data and how much.
- Contract for breach notification timelines and cooperation.
- Minimize data shared with SaaS providers — delete historic records you don't need.
- Plan your own notification process for vendor breaches.
In hindsight
Blackbaud became a reference case for SaaS supply-chain risk and for honest disclosure. Similar patterns followed with MOVEit (2023) and Snowflake customers (2024): one vendor incident cascading into hundreds of customer notifications.
- How to Assess SaaS Vendors' Security Before You Sign How-To & Hardening
- Monitoring Third-Party SaaS Risk Signals and Breach Notifications Detection & Response
- CIO Brief: Third-Party Ransomware and Your Disclosure Obligations CIO Briefings