Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Third-Party Ransomware and Your Disclosure Obligations

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers had to notify their own donors and students. Years later, regulators penalized Blackbaud for misleading disclosures.

Why a vendor's ransomware is your incident

When a vendor holding your data is breached, your obligations don't disappear. You may need to notify the people affected, answer regulators and handle the reputational fallout — often with incomplete information from the vendor.

The business impact

  • Notification costs and staff time.
  • Reputational damage with customers, donors or patients.
  • Regulatory exposure, especially in healthcare, education and finance.
  • Uncertainty, when the vendor's account of events changes.

Questions to ask your team

  • Which vendors hold our most sensitive data?
  • What do our contracts require them to tell us, and how quickly?
  • Do we have a plan to notify affected people if a vendor is breached?
  • Could we reduce the data we share with them?

What good looks like

A ranked list of high-risk vendors, strong contract terms, minimal data shared, and a ready-to-use vendor breach response plan.

The decision

Ask legal and IT to run a short exercise: "Our largest data vendor announces a ransomware attack today." The gaps it reveals are usually inexpensive to fix in advance.

blackbaud breach impactBlackbaud2020

More on this story