Nonprofit Organizations · Cybersecurity Training

Nonprofits Are the #1 Target for BEC and Ransomware

Donor CRM breaches, grant wire fraud, and donor PII exposure are costing nonprofits millions. One training program can change that — and satisfy IRS Pub 4557 requirements while you're at it.

4th Most-targeted sector by nation-states
$2.77B BEC losses reported to FBI IC3 in 2024
$183K Avg BEC loss for nonprofits in 2024 (+118%)

Recent incidents that defined the nonprofit threat landscape

Blackbaud Ransomware — May 2020
13,000+ nonprofit clients affected
Serves 80% of top nonprofits. $49.5M+ in settlements. Donor CRM systems held hostage for days — data exposure across the entire sector.
Save the Children Federation — 2017
$997,400 wired via BEC (~$112K net loss)
Hacked employee email + fake invoices for Pakistan solar panels. Net loss ~$112K after insurance. One of the highest-profile nonprofit BEC cases on record.
One Treasure Island — 2021
$650,000 wired via BEC ($613K unrecovered)
Fake bank audit emails delayed detection for weeks. Single donor-facing staff member clicked through the entire attack chain.
Brunswick, Ohio Parish — 2019
$1.75M church construction payment redirected
Marous Brothers construction firm BEC. $1.75M wired to fraudsters. Insurance recovery, legal action, and donor trust damage took years to repair.

Five vulnerabilities unique to the nonprofit sector

Nonprofits face a combination of high-value targets, thin security infrastructure, and organizational culture that attackers specifically exploit. Here's where your exposure lives.

💸

Grant Disbursement Payment Flows

Grant payouts involve multiple approval stages, international wires, and tight deadlines — perfect for BEC. Q3 disbursement requests from "program officers" asking for last-minute bank account changes are a documented attack pattern for FEMA NSGP recipients and foundation grantees.

🖥️

Thin IT Budgets

Most nonprofits run on minimal security tooling — if any at all. No dedicated IT staff, no email filtering, no MFA on critical systems. The Blackbaud ransomware event hit 13,000+ organizations because many had no backup communications channel when their CRM went dark.

🤝

Trust-Based Organizational Culture

Nonprofits are mission-driven organizations where staff are conditioned to be helpful and responsive. That culture makes employees more susceptible to social engineering — especially authority-based requests ("This is the ED, we need this done now").

👤

Donor PII = High-Value Data

Donor databases contain names, addresses, giving history, credit cards, and sometimes SSNs (for stock donations). This data is gold for identity theft and phishing campaigns. Blackbaud's breach exposed donor information from 13,000+ nonprofits — and attackers know exactly what's in those systems.

📋

FEMA NSGP Grant Exposure

$274.5M in FEMA Nonprofit Security Grant Program funds available FY2025. Organizations receiving NSGP grants are in active conversations with government agencies — making them prime targets for impersonation campaigns, fake program officer requests, and grant wire fraud.

When it went wrong — and what it cost

Donor CRM · May 2020

Blackbaud Ransomware

13,000+ nonprofit clients. Blackbaud paid the ransom and delayed disclosure. $49.5M+ in multistate settlements (SEC Press Release 2023-48, NJ OAG). The delay meant nonprofits lost weeks of donor communication capability and legal coordination. 80% of the top nonprofits in the US were affected.

13,000+ Nonprofit clients affected · $49.5M+ settlement
Humanitarian · 2017–2018

Save the Children Federation

BEC via compromised employee email. $997,400 wired to Japan via fake invoices for Pakistan solar panel project. ~$112K net loss after insurance recovery. Boston Globe (Dec 2018), AP News confirmed. One of the first high-profile nonprofit BEC cases to receive widespread media coverage.

$997K Wired · ~$112K net loss after insurance
Community · 2021

One Treasure Island

$650,000 wired via BEC. $613K unrecovered. Fake bank audit emails delayed discovery for weeks. Single staff member initiated the transfer. SF Chronicle (May 2021) reported the full attack chain. OTI rebuilt its programs over two years to recover from the loss.

$650K Wired · $613K unrecovered
Religious · 2019

Brunswick, Ohio Parish

$1.75M in church construction payments redirected via BEC (Marous Brothers construction firm vendor compromise). Insurance recovery and legal action recovered some funds over time. Threatpost (2019) confirmed the full amount and attack method. Donor trust in the parish took years to rebuild.

$1.75M Redirected via BEC · multi-year recovery

The nonprofit compliance stack — what you actually have to do

Nonprofits have specific regulatory obligations that extend beyond general data security. Here's what applies and what happens when you don't comply.

IRS Publication 4557 — WISP Required

501(c)(3) organizations collecting W-9s, processing 1099s, or handling donor PII must implement a Written Information Security Plan. The WISP must include 'periodic security awareness training' for all employees who handle taxpayer information. This is not optional — it's an IRS requirement for any nonprofit processing 1099s.

FTC Safeguards: $46,517/violation/day

FEMA NSGP — $274.5M Available FY2025

The Nonprofit Security Grant Program funds cybersecurity training and preparedness for eligible nonprofits. Training is an allowable use of NSGP funds. Organizations receiving NSGP should document their training programs as part of grant compliance and reporting requirements.

Grant compliance documentation required

State Charity Registration — Data Handling

Most states require charities to register with the state attorney general and comply with data handling requirements as part of registration. A data breach affecting donor information may trigger notification obligations under state charity law in addition to state breach notification statutes.

AG notification · state-specific timelines

Donor Privacy / CCPA

Nonprofits with California donors or revenue exceeding $20M must comply with CCPA/CPRA obligations for donor PII. This includes the right to opt out of data sales (even if you don't 'sell' data in the traditional sense, some third-party data-sharing arrangements qualify), privacy notice requirements, and data deletion obligations.

CCPA/CPRA: $2,500-$7,500/violation

Three drills your nonprofit team needs — built for actual nonprofit workflows

Generic security training doesn't address the specific attack patterns hitting nonprofits. These three drills are built around the exact workflows — grant disbursements, donor CRM access, and executive impersonation — that make nonprofits vulnerable.

Drill 1 · Finance & Development
💸

Grant Disbursement BEC Simulation

Walk your finance and development staff through the exact BEC pattern targeting grant disbursement wires — "program officer" emails requesting bank account changes for Q3 grant payments, fake FEMA correspondence, and urgency pressure from fake ED communications.

  • Callback verification protocol for any grant wire request
  • Dual authorization for payment account changes
  • Documenting the grant approval workflow for audit trail
  • How to verify FEMA NSGP correspondence authenticity
  • What to do if a grant wire has already been sent
Drill 2 · Development & Program Staff
🎣

Donor CRM Phishing Scenario

Blackbaud's 2020 breach exposed 13,000+ nonprofit donor databases. This drill covers phishing campaigns impersonating Blackbaud login pages, Salesforce Nonprofit CRM credential requests, and fake donor thank-you emails with malicious links.

  • Spotting lookalike Blackbaud and CRM login pages
  • No-click policy for unexpected login emails
  • Phishing simulation for donor-facing staff
  • MFA enrollment on all CRM admin accounts
  • What to do if donor data export was triggered by an attacker
Drill 3 · Leadership & Admin
🎭

Executive Director Impersonation Drill

Your ED's name and email are public information on your website and 990 filings. Attackers use that to impersonate executives in urgent, high-pressure requests for immediate wire transfers or credential sharing — bypassing normal approval processes.

  • Urgency and pressure recognition — the ED never needs 2 hours
  • Out-of-band verification for any executive wire request
  • Bypassing approval chains and what to do when asked
  • How to verify an ED request via a known-good phone number
  • Incident response if an executive account is confirmed compromised

Free playbooks and tools for nonprofit security teams

These free resources cover the specific attack patterns and compliance requirements nonprofits face. Download them and use them to build your security program.

One price. Unlimited sessions.

No per-seat licensing. No annual contracts. Book a session, train your team, satisfy IRS Pub 4557.

Individual Contributor — Personal
$150
Per person, per session. 60-minute personalized session for program staff, development officers, and finance team members.
  • 60-minute personalized coaching
  • BEC verification drill for grant disbursements
  • Donor CRM phishing recognition
  • Printed checklist for your desk
Secure Your Team →
Executive — Business
$900
Unlimited users, per session. Firm-wide training with custom tabletop exercises and board briefing.
  • 120-minute firm-wide session
  • All 3 drills + board fiduciary briefing
  • IRS Pub 4557 documentation package
  • FEMA NSGP grant security checklist
  • Ongoing coaching access for 30 days
Get a Threat Assessment →

Questions from nonprofit teams

Does IRS Publication 4557 actually require cybersecurity training for nonprofits?

Yes — IRS Publication 4557 explicitly requires 501(c)(3) organizations that collect W-9s, process 1099s, or handle donor PII to implement a Written Information Security Plan (WISP). The WISP must include 'periodic security awareness training' for employees. Failure to comply can result in FTC Safeguards Rule civil penalties up to $46,517 per violation per day. For a nonprofit that processes thousands of donor records annually, a single breach traced back to inadequate training is a seven-figure liability on top of the breach itself.

Why are nonprofits specifically targeted for BEC and wire fraud?

Nonprofits face a perfect storm: thin IT budgets mean minimal email security tooling, trust-based organizational culture makes staff more susceptible to authority-based social engineering, and the complexity of grant disbursements with multiple approval stages creates exploitable friction points. Organizations processing FEMA NSGP grants ($274.5M available in FY2025) are especially attractive targets because grant disbursements are large, often involve international wire transfers, and operate under time pressure. The average BEC loss for nonprofits hit $183,000 in 2024 — up 118% from 2023.

How do I protect donor CRM data from phishing and credential theft?

Your donor CRM (Blackbaud, Salesforce Nonprofit CRM, Bloomerang) holds some of the highest-value personal data a nonprofit touches — donor names, giving history, addresses, sometimes SSNs for stock donations. Phishing campaigns impersonating Blackbaud login pages are documented. The defense: phishing-resistant MFA for all CRM logins (especially admin accounts), out-of-band verification for any request to change banking details or export large donor segments, email authentication (SPF/DKIM/DMARC) to block spoofed domains, and regular training so staff recognize credential phishing attempts. Blackbaud's own 2020 ransomware breach affected 13,000+ nonprofit clients — the lesson is that your CRM vendor's security is your security.

Can FEMA NSGP grant funds be used for cybersecurity training?

Yes — the Nonprofit Security Grant Program (NSGP) under FEMA's FY2025 allocation ($274.5M) explicitly lists 'training' as an allowable expenditure. Organizations can use NSGP funds to train staff on threat recognition, incident response, and grant-specific cybersecurity requirements. This creates a funding path for security training that doesn't compete with program budgets. SecurEveryone training qualifies under NSGP's training and preparedness categories. Ask your grant administrator or FEMA's NSGP program office for the current allowable cost guidance.

What makes a nonprofit's incident response plan different from a for-profit company's?

Three things: donor notification obligations vary by state and may include AG notification even for small breaches, grant compliance requirements may mandate specific notification timelines to funders, and the board of directors for a 501(c)(3) has fiduciary responsibilities around data protection that are distinct from corporate directors. A nonprofit incident response plan must account for donor communication protocols, state charity registration obligations, grant agreement notification requirements, and board liability considerations — none of which appear in a standard corporate IR plan. SecurEveryone's IR Plan Template includes a nonprofit-specific addendum covering these nuances.

Your donors and grantees are counting on your team to protect their data

Book a live session today. Sessions are 60–120 minutes, held over Zoom, and built around your specific nonprofit workflows — grant disbursements, donor CRM access, and executive communications.

SecurEveryone · IRS Pub 4557 / FEMA NSGP / FTC Safeguards · $150–$900 · Live expert coaching