Non-profit

Non-profit organization data breaches expose donor financial information, employee and volunteer personal records, and sometimes sensitive data about the individuals a non-profit serves, such as clients of a healthcare, housing, or social services organization. These exposures can lead to identity theft, direct financial fraud, and scams that specifically target donors using stolen names, giving histories, and contact information to impersonate the organization or solicit further payments. Non-profits are frequently under-resourced when it comes to cybersecurity relative to the amount and sensitivity of the data they collect, which can make them attractive targets despite operating on limited budgets. Depending on the organization’s mission, a breach may also expose especially sensitive information about vulnerable populations the non-profit serves, raising additional privacy concerns beyond typical financial data. This page tracks confirmed data breaches at non-profit organizations, including what data was exposed, which companies notified regulators, and what affected individuals can do next to protect themselves.

Beech Acres Data Breach: Sensitive Personal Data Exposed – What You Must Know

A person wearing a Guy Fawkes mask engaged in hacking activities on a computer in a dimly lit room.

Beech Acres, a nonprofit serving families and clients, discovered unauthorized network access on November 23, 2024, later confirming hackers accessed sensitive data including names, Social Security numbers, driver's license numbers, bank account details, and medical and health insurance records. Affected clients and stakeholders face identity theft and fraud risks. Anyone notified should immediately enroll in […]

Beech Acres Data Breach: Sensitive Personal Data Exposed – What You Must Know Read More »

BYU-Pathway Data Breach Exposes Student Information Through Compromised Vendor Account

Students at BYU

In June 2025, BYU-Pathway Worldwide suffered a breach after a vendor account was compromised, giving an unknown attacker access between roughly June 17 and June 24. Affected students and users may have had names, Social Security numbers, account IDs, contact details, gender, marital status, religious affiliation, age, and course history exposed. Affected individuals should immediately

BYU-Pathway Data Breach Exposes Student Information Through Compromised Vendor Account Read More »