FTC orders Blackbaud to delete data and improve security practices after 2020 breach

Blackbaud has agreed to delete excess sensitive data it held about its customers and completely review its data retention and data security policies as part of the settlement it was formalized at the Federal Trade Commission (FTC), following a catastrophic data breach in 2020.

Blackbaud was breached in February 2020 by unnamed threat actors. The hackers targeted the company’s infrastructure for three months, quietly identifying and exfiltrating sensitive data. By the time they were done, they had siphoned off files from about 13,000 Blackbaud customers.