This Is How a Nonprofit Gets Breached

Most people picture a breach as a dramatic event. A hacker breaking through a firewall. Alarms going off. Someone noticing immediately.

That is not how it happens.

In most cases, by the time anyone inside the organization realizes something is wrong, the attacker has been inside for days or weeks. The breach already happened. What follows is damage control.

Here is how it actually unfolds.

It Starts With One Credential

A staff member gets an email. It looks like it came from Microsoft, or their bank, or a vendor they work with. The subject line says something routine: “Verify your account,” or “Action required on your invoice,” or “Update your login before access expires.”

They click the link. The page looks right. They enter their username and password.

Nothing happens. Maybe they get an error message and try again. Maybe they close the browser and move on with their day.

What they do not know is that the page was fake. Their credentials went to an attacker.

The Attacker Waits

This is the part that surprises most people.

Attackers do not always act immediately after getting into an account. In many cases, they spend time observing. They read email. They learn who the finance director is. They understand how funds move through the organization. They identify upcoming grant disbursements, vendor payments, or donor transfer schedules.

They are building a picture. The longer they wait undetected, the more useful their access becomes.

During this period, the staff member whose account was compromised notices nothing. Email is working. Files are accessible. Everything looks normal.

The Attack Moves

When the attacker is ready, they act.

In a business email compromise scenario, they send a message from the compromised account, or a convincing imitation of it, to the finance team. The message requests a change to a vendor’s bank routing number before an upcoming payment. It references the real vendor. It uses the right tone. It comes from what looks like a trusted source.

The finance team follows their normal process. The payment goes out.

In a ransomware scenario, the attacker uses the access to move laterally across the network, accessing shared drives and backup systems. Then they encrypt everything and send a ransom demand.

In a data theft scenario, they export the donor database, the beneficiary records, or the grant management files. The data goes to a criminal forum or gets used directly for identity theft and fraud.

The Discovery

Discovery often happens by accident.

A staff member notices they cannot log into an account. Someone sees a transaction that does not match any approved invoice. A donor calls to report a suspicious email that appeared to come from the organization.

By that point, the window for containment has already closed in most cases. The attacker is done. The data is gone or the files are encrypted.

The organization is left figuring out what happened, how much was exposed, who needs to be notified, and what it will take to recover.

What Nonprofit Staff Actually Deal With

Notification requirements under state data breach laws apply to nonprofits the same as for-profit companies. If donor payment data was exposed, the organization may need to notify affected individuals within a specific timeframe. Failure to notify on time creates legal exposure.

Donors lose confidence. Some leave. Grant funders ask questions. Board members want answers. The executive director is spending time managing the fallout instead of running programs.

The average data breach costs a nonprofit $200,000. That number includes direct costs like notification, credit monitoring, and legal fees. It does not fully capture the operational disruption, staff time, and long-term reputational impact.

What Stops It Before It Starts

Multi-factor authentication on email accounts would have stopped the credential theft in the opening scenario. Even if the staff member entered their password on a fake page, the attacker would not have been able to log in without the second factor.

Email filtering that flags messages from outside the organization with visual indicators helps staff recognize when something came from an unexpected source.

Training that shows staff what a phishing attempt looks like, using real examples, makes the population of people who click on fake links smaller.

None of these are expensive. None require a dedicated security team. They require a decision to build them into how the organization operates.

The breach described above is not a worst-case scenario. It is a common one. The organizations that avoid it are not the ones with the biggest security budgets. They are the ones that made the basics a priority before something went wrong.


NexSecure Solutions helps nonprofits and small businesses build security programs that fit their actual capacity. Schedule a free discovery call.

Categories: