Blackbaud, a leading cloud software provider based in Charleston, South Carolina, USA, that was attacked by ransomware last May, has confirmed that the hackers behind it gained access to unencrypted banking data, credentials, and social security numbers. The company operates not only in the US but also in other countries, including the UK, Australia, and Canada.

The ransomware attack that took place last May at Blackbaud was revealed in a press release issued on July 16, when the company said the attackers were stopped before they could fully encrypt systems . However, they managed to steal a copy of a subset of data from a private cloud. Blackbaud then paid the ransomafter the hackers assured it that they had destroyed the stolen data.

The ransomware attack on Blackbaud affected a large number of organizations around the world, including charities, non-profits, and universities in the US, Canada, the UK, and the Netherlands.
While Blackbaud initially said that the hackers behind the ransomware attack did not gain access to credit card information, bank account details and social security numbers, after a thorough investigation it discovered that the hackers ultimately had access to unencrypted banking data, credentials and social security numbers. However, the company clarified that these new findings do not apply to all customers affected by the security incident.

Blackbaud also said that the investigation is still ongoing, and the company will continue to update customers, shareholders and other stakeholders on any new developments.
Depending on the ransomware gang that stole Blackbaud's data, its willingness to destroy it, and what it plans to do with it if it doesn't destroy it as promised, the company's customers could face multiple security risks, considering the sensitive nature of the exposed information.
According to BleepingComputer, there are, to our knowledge, 22 ransomware operations that steal sensitive documents from servers before encryption. Furthermore, the data that hackers steal in these attacksis later used to threaten victims to pay a ransom, otherwise the stolen data will be leaked gradually until the ransom is paid. In some cases, the ransom may even increase until all the stolen data is leaked to data leak sites or hacking forums. The Maze ransomware group was the first to publish the stolen data of Allied Universal, because the latter refused to pay the ransom demanded in November 2019.
