
At least 10 universities in the UK, US and Canada have been hit by breach datafollowing a hack at cloud computing provider Blackbaud.
The non-governmental organization Human Rights Watch and the children's mental health charity Young Mindsalso confirmed that they were affected by the attack.
The hack targeted the company Blackbaud, one of the largest providers of education software, fundraising and financial management.
The hack into systems took place in May.
The provider has been heavily criticized for not immediately disclosing the incident. The disclosure to affected parties was made in July. The company said it paid a ransom, but did not disclose the exact amount.
In some cases, the data breach was limited to former students, who were asked to financially support the institutions they had graduated from. But in other cases, data on staff, current students, and other collaborators was exposed.
The universities and institutions affected by the Blackbaud hack are:
- University of York
- Oxford Brookes University
- Loughborough University
- University of Leeds
- University of London
- University of Reading
- University College, Oxford
- Ambrose University in Alberta, Canada
- Human Rights Watch
- Young Minds
- Rhode Island School of Design in the US
- University of Exeter
All institutions are sending letters and emails to apologize to users whose data was in the compromised databases.

In some cases, the stolen data included phone numbers, donation history, and events the victims had attended. information and other payment details do not appear to have been exposed.
Blackbaud, whose headquarters are in South Carolina, refused to provide full lists of those affected, saying it wanted to “respect its customers’ privacy.”.
“The majority of our customers were not affected by this incident,” the company.
Blackbaud said: “In May 2020, we discovered and stopped a ransomware. The criminal managed to remove a copy of a subset of our data.”
The statement goes on to say that Blackbaud paid the ransom. This is not illegal, but it goes against the advice of security and law enforcement agencies, including the FBI, NCA, and Europol.
Blackbaud added that their hackers assured them they destroyed the data after payment.
Several customers (including some universities) of Blackbaud confirmed that they were not affected by the hack:
- University College London
- Queen’s University Belfast
- University of the West of Scotland
- Islamic Relief
- Prevent Breast Cancer
Rhys Morgan, a cybersecurity specialist and former student of Oxford Brookes University (his data is still in the university's databases), is uncertain about the security of his data.
"They told my university that there is no reason to believe that the stolen data was or will be used for any malicious purpose."
“This does not reassure me at all. How can they know what the attackers will do with this information”;
Following the hack, Blackbaud said it was working with law enforcement and investigators to find out if the data was being circulated or sold online and on the dark web.
Privacy Law
Under the General Data Protection Regulation (GDPR), companies must report data breach incidents to the authorities within 72 hours of discovering the incidents, otherwise they will be fined.
Apparently, the authorities of the United Kingdom [ICO] and Canada were informed about the breach last weekend, many weeks after the hack was discovered by Blackbaud.
