FTC orders Blackbaud to delete data, up security practices following 2020 breach

Posted by

Blackbaud has agreed to delete excess sensitive data it held on its customers, and completely revamp its data retention and data security policies as part of the settlement it formalized with the Federal Trade Commission (FTC), following a catastrophic data breach that happened in 2020.

Blackbaud was breached in February 2020 by unnamed threat actors. The hackers dwelled on the company’s infrastructure for three months, quietly identifying and exfiltrating sensitive data. By the time they were done, they siphoned out files on roughly 13,000 Blackbaud customers.