Non-profit

Non-profit organization data breaches expose donor financial information, employee and volunteer personal records, and sometimes sensitive data about the individuals a non-profit serves, such as clients of a healthcare, housing, or social services organization. These exposures can lead to identity theft, direct financial fraud, and scams that specifically target donors using stolen names, giving histories, and contact information to impersonate the organization or solicit further payments. Non-profits are frequently under-resourced when it comes to cybersecurity relative to the amount and sensitivity of the data they collect, which can make them attractive targets despite operating on limited budgets. Depending on the organization’s mission, a breach may also expose especially sensitive information about vulnerable populations the non-profit serves, raising additional privacy concerns beyond typical financial data. This page tracks confirmed data breaches at non-profit organizations, including what data was exposed, which companies notified regulators, and what affected individuals can do next to protect themselves.