TORONTO — At least two prominent fundraising organizations in Canada have notified their donors that their personal information may have been compromised in a May ransomware attack.
Ransomware is a type of software designed to lock an information server and prevent it from being used by the host organization unless a payment is made, often in the form of a cryptocurrency such as bitcoin. In this case, an unspecified amount was paid by a U.S. company that says it successfully prevented the information from being transmitted beyond the hacker.
The Centre for Addiction and Mental Health in Toronto and Western University in London, Ont., advised donors recently by email that a ransom was paid by Blackbaud Inc., one of their service providers.
The South Carolina-based company specializes in providing cloud services to manage fundraising efforts by charitable foundations around the world. It posted a notification of the ransomware attack on its website earlier this month, several weeks after it became aware of the attack.
Blackbaud did not respond to requests for further information about how many of its Canadian clients were affected but its website lists several Canadian foundations affiliated with hospitals, charities and not-for-profit organizations.
But CAMH and Western noted in their communications that the attacker would have had access to individual names, dates of birth, contact information, donations or engagement with the fundraising organizations — information that can be bought and sold by criminal organizations around the world.
CAMH Foundation and Western assured their donors they’d be notified “immediately” if more of their information had been compromised.
“In addition to notifying all potentially affected parties directly, we are working closely with Blackbaud to understand why this happened, what data was impacted, and what actions they are taking to increase their security,” the CAMH letter said.
“While this did not affect the Foundation’s IT systems and infrastructures, we wish to assure you that we have robust protocols in place, and are continually keeping up with industry standards, including testing the security of our internal systems to be assured that the information we host is secure.”
CAMH said in a statement Thursday it would issue further updates if the situation evolves.
A request for more information from Western was referred to its media department but there was no immediate response Thursday.
A notice Western sent last week said the university had notified privacy officials and recommended that donors contact local law enforcement if they see any suspected identity theft or other suspicious use of their personal information.
Western also said it had suspended the use of Blackbaud “for the time being” while it investigated the incident.
Blackbaud officials said Thursday during a regular quarterly conference call with analysts that its own security personnel and outside experts, including law enforcement, have found no reason to believe any data went beyond the cybercriminal or will make available publicly.
“I’d just like to apologize on behalf of Blackbaud for the incident,” said CEO and president Mike Gianoni. “Like a lot of companies, we get millions of intrusion attempts a month. And unfortunately, one got in to a subset of our customers and a subset of our backup environment.”
Blackbaud is a well-established company that generated US$900.4 million in annual revenue last year. In the second quarter ended June 30, which included the ransomware attack, it reported US$11.8 million of net income, up from US$7.14 million a year ago.