A treasurer at a humanitarian nonprofit receives an email that appears to come from a government agency, asking him to send a file with donor bank details. The logo looks right, the tone is official. He complies. Three days later, fraudulent transactions start appearing. It was a targeted phishing attack, and it worked because nobody was prepared.
This kind of incident happens regularly in the nonprofit sector. Nonprofits are not random targets: they hold sensitive data and often lack the protections that businesses have put in place.
Why nonprofits are targets
Cyber criminals do not choose their victims by size or budget. They look for the easiest route to exploitable data. A nonprofit with 500 members, their contact and banking details, and no multi-factor authentication or tested backups is an easier target than a well-protected SME.
The data nonprofits hold is genuinely valuable: full contact records, bank details for recurring donations, sometimes medical or social data for frontline organisations. A breach directly exposes your donors and can trigger a regulatory investigation.
The most common attacks
Phishing is still the most frequent threat. Messages are increasingly convincing, sometimes personalised using details from your public communications. Treasurers and directors are particularly targeted, because they have access to bank accounts.
Ransomware encrypts all your data and demands payment to restore it. For a nonprofit without tested backups, this can mean losing years of records.
Both attacks exploit human and organisational weaknesses as much as technical ones.
Practical measures to put in place
Multi-factor authentication on every account: email, collaboration tools, banking access. This single measure gives the best protection-to-effort ratio available. A stolen password is no longer enough to take control of an account.
Regular, tested backups. An untested backup is not a backup. At minimum, keep a copy offsite and verify regularly that restoration actually works.
Access controls. Each volunteer or staff member should only be able to access the data they need for their role. A communications volunteer does not need to see the full donor list with amounts.
Staff training. One hour of awareness training per year significantly reduces phishing risk. Teach your team to check sender addresses carefully, to never transmit sensitive data by email without a phone confirmation, and to report suspicious messages.
What the law requires
You are responsible for the data you collect. In the event of a breach, you must notify the relevant authority within 72 hours and inform the individuals affected. In the most serious cases, penalties can reach 4% of annual turnover. This isn’t meant to frighten you; it is simply the legal reality you are responsible for. Beyond the legal risk, a donor data breach destroys trust that took years to build.
To find out how InfraPro supports nonprofits with IT security, visit /en/nonprofits/.
