2023-03-09 SEC Press press_release 61 KB 2,226 chars

SEC Charges Software Company Blackbaud Inc. for Misleading Disclosures About Ransomware Attack That Impacted Charitable Donors

Release
2023-48
Caption
Securities and Exchange Commission v. Blackbaud Inc., et al.
summary

Blackbaud Inc

paragraph

Blackbaud Inc. is accused of making misleading disclosures about a 2020 ransomware attack that impacted over 13,000 customers. The alleged fraud involved the company's failure to disclose that the attacker had accessed and exfiltrated sensitive donor information, including bank account numbers and social security numbers, despite earlier statements claiming this information was not accessed. Blackbaud agreed to pay a $3 million civil penalty to settle charges of violating the Securities Act of 1933 and the Securities Exchange Act of 1934. The company was charged with violating multiple provisions, including Sections 17(a)(2) and 17(a)(3) of the Securities Act and Section 13(a) of the Securities Exchange Act. Without admitting or denying the findings, Blackbaud agreed to cease and desist from committing similar violations.

narrative

Blackbaud Inc. is accused of making misleading disclosures about a 2020 ransomware attack that impacted over 13,000 customers. The alleged fraud involved the company's failure to disclose that the attacker had accessed and exfiltrated sensitive donor information, including bank account numbers and social security numbers, despite earlier statements claiming this information was not accessed. Blackbaud agreed to pay a $3 million civil penalty to settle charges of violating the Securities Act of 1933 and the Securities Exchange Act of 1934. The company was charged with violating multiple provisions, including Sections 17(a)(2) and 17(a)(3) of the Securities Act and Section 13(a) of the Securities Exchange Act. Without admitting or denying the findings, Blackbaud agreed to cease and desist from committing similar violations. Blackbaud Inc., a South Carolina-based donor data software provider, agreed to pay a $3 million civil penalty to settle SEC charges for making misleading disclosures about a July 2020 ransomware attack that compromised sensitive donor data, including bank account and Social Security information, affecting over 13,000 customers. Despite internal knowledge within days of the breach that the attacker had exfiltrated sensitive data, Blackbaud failed to update its public statements or disclose this material information in its August 2020 SEC filing, due to deficient disclosure controls. The SEC found violations of Sections 17(a)(2) and 17(a)(3) of the Securities Act and Section 13(a) of the Exchange Act, along with related rules, for omitting material facts and making false representations. Blackbaud consented to a cease-and-desist order without admitting or denying the findings, and the SEC’s investigation was supported by the FTC and state attorneys general. Blackbaud Inc., a donor data software provider, agreed to pay a $3 million civil penalty to settle SEC charges for making misleading disclosures about a July 2020 ransomware attack that compromised sensitive donor data, including bank account and Social Security numbers, affecting over 13,000 customers. Despite internal knowledge within days of the breach that the attacker had exfiltrated this sensitive information, Blackbaud failed to update its public statements or disclose the true scope in its August 2020 SEC filing, due to deficient disclosure controls. The SEC found violations of Sections 17(a)(2) and 17(a)(3) of the Securities Act and Section 13(a) of the Exchange Act, along with related rules, for omitting material facts and mischaracterizing risks as hypothetical. Blackbaud consented to a cease-and-desist order without admitting or denying the findings. The investigation was led by the SEC’s Crypto Assets and Cyber Unit, with assistance from the FTC and state attorneys general.

Enriched metadata

Scheme
cyber-fraud (95%)
Outcome
settled
Settlement
$3,000,000
Civil penalty
$3,000,000
Victims
13,000
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
blackbaud inc.brent wilnersec investigation
Keywords
secblackbaudransomware attackcompanyattackinformationmisleading disclosuresdisclosures aboutabout ransomwareattack impactedorder findsaboutransomwarepublicsoftware company

Exhibits & Attached Documents (1)

Extracted insights

Dollar amounts 1
  • $3.00M $3 million $1M–$10M
Entities 3
  • company blackbaud inc.
  • person brent wilner
  • agency sec investigation
Triples 8
  • Blackbaud Inc. Agreed To Pay $3 million
  • Blackbaud Announced Ransomware Attacker Did Not Access Donor Bank Account Information Or Social Security Numbers
  • Company’s Technology And Customer Relations Personnel Learned Attacker Accessed And Exfiltrated Sensitive Information
  • Employees Did Not Communicate This Information To Senior Management
  • Blackbaud Failed To Disclose Full Impact Of Ransomware Attack
  • Blackbaud Agreed To Cease And Desist Committing Violations Of Provisions
  • SEC Investigation Was Conducted By Brent Wilner
  • SEC Investigation Was Supervised By Diana Tani, Carolyn Welshhans, And Mr. Hirsch
PDF (from attached: pdf)
Text layers
Extracted body text (2,226c)
The Securities and Exchange Commission today announced that Blackbaud Inc., a South Carolina-based public company that provides donor data management software to non-profit organizations, agreed to pay $3 million to settle charges for making misleading disclosures about a 2020 ransomware attack that impacted more than 13,000 customers. The SEC’s order finds that, on July 16, 2020, Blackbaud announced that the ransomware attacker did not access donor bank account information or social security numbers. Within days of these statements, however, the company’s technology and customer relations personnel learned that the attacker had in fact accessed and exfiltrated this sensitive information. These employees did not communicate this information to senior management responsible for its public disclosure because the company failed to maintain disclosure controls and procedures. Due to this failure, in August 2020, the company filed a quarterly report with the SEC that omitted this material information about the scope of the attack and misleadingly characterized the risk of an attacker obtaining such sensitive donor information as hypothetical. “As the order finds, Blackbaud failed to disclose the full impact of a ransomware attack despite its personnel learning that its earlier public statements about the attack were erroneous,” said David Hirsch, Chief of the SEC Enforcement Division’s Crypto Assets and Cyber Unit. “Public companies have an obligation to provide their investors with accurate and timely material information; Blackbaud failed to do so.” The SEC's order finds that Blackbaud violated Sections 17(a)(2) and 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Securities Exchange Act of 1934 and Rules 12b-20, 13a-13, and 13a-15(a) thereunder. Without admitting or denying the SEC’s findings, Blackbaud agreed to cease and desist from committing violations of these provisions and to pay a $3 million civil penalty. The SEC’s investigation was conducted by Brent Wilner and supervised by Diana Tani, Carolyn Welshhans, and Mr. Hirsch. The SEC appreciates the assistance of the Federal Trade Commission and the Offices of the Attorneys General for the States of Indiana and Vermont.
OCR text (2,226c · html-text · 99% conf)
The Securities and Exchange Commission today announced that Blackbaud Inc., a South Carolina-based public company that provides donor data management software to non-profit organizations, agreed to pay $3 million to settle charges for making misleading disclosures about a 2020 ransomware attack that impacted more than 13,000 customers. The SEC’s order finds that, on July 16, 2020, Blackbaud announced that the ransomware attacker did not access donor bank account information or social security numbers. Within days of these statements, however, the company’s technology and customer relations personnel learned that the attacker had in fact accessed and exfiltrated this sensitive information. These employees did not communicate this information to senior management responsible for its public disclosure because the company failed to maintain disclosure controls and procedures. Due to this failure, in August 2020, the company filed a quarterly report with the SEC that omitted this material information about the scope of the attack and misleadingly characterized the risk of an attacker obtaining such sensitive donor information as hypothetical. “As the order finds, Blackbaud failed to disclose the full impact of a ransomware attack despite its personnel learning that its earlier public statements about the attack were erroneous,” said David Hirsch, Chief of the SEC Enforcement Division’s Crypto Assets and Cyber Unit. “Public companies have an obligation to provide their investors with accurate and timely material information; Blackbaud failed to do so.” The SEC's order finds that Blackbaud violated Sections 17(a)(2) and 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Securities Exchange Act of 1934 and Rules 12b-20, 13a-13, and 13a-15(a) thereunder. Without admitting or denying the SEC’s findings, Blackbaud agreed to cease and desist from committing violations of these provisions and to pay a $3 million civil penalty. The SEC’s investigation was conducted by Brent Wilner and supervised by Diana Tani, Carolyn Welshhans, and Mr. Hirsch. The SEC appreciates the assistance of the Federal Trade Commission and the Offices of the Attorneys General for the States of Indiana and Vermont.