FTC orders Blackbaud to overhaul ‘reckless’ security practices in wake of 2020 breach
ID: 9f9650c0-b3c3-5761-a4eb-dab789ad22b3
STIX ID: report--9f9650c0-b3c3-5761-a4eb-dab789ad22b3
Feed Name: TechCrunch Security News
Blackbaud agreed to settle with the U.S. FTC over lax security that enabled a February 2020 breach: attackers used a customer credential to remain in Blackbaud’s network for months, exfiltrating millions of consumers' unencrypted sensitive records (including Social Security and bank account numbers) and receiving a roughly $250,000 ransom. The FTC alleges failures including inadequate encryption, lack of multi-factor authentication, poor monitoring and patching, weak password practices, and excessive data retention; the settlement requires deletion of unnecessary data and cybersecurity reforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
