Why nonprofits have become a prime target for cyberattacks

Travelers' Erin Ramsey talks about the donor data risk most nonprofit boards haven't priced in

Why nonprofits have become a prime target for cyberattacks

Risk Management News

By Mark Rosanes

Cybercriminals don't pick their targets the way most nonprofit leaders assume. They look for accessible vulnerabilities first, then assess what sensitive data they can monetize.

Erin Ramsey (pictured), cyber risk product manager at Travelers, explains why that search is landing on nonprofits more often and what risk managers can do about it. She also addresses the security gaps the sector most commonly overlooks, and the practical steps organizations can take to close them.

What makes nonprofit data attractive

Cybercriminals don't rank victims by revenue or profile. They find a network entry point, then assess what data is worth taking. Nonprofits hold more of that than most boards recognize.

"Cybercriminals usually don't target specific companies or organizations," Ramsey said. "They target computer vulnerabilities, and once they access a network, they look for sensitive data they can monetize and that the victim is committed to protecting."

Nonprofit data meets both criteria, Ramsey said. "Since many nonprofits store sensitive financial information - donor lists, amounts pledged, bank account details - suffering any kind of unauthorized breach can be incredibly damaging to an organization and lead to harmful results."

The reputational exposure can be just as difficult to manage as the financial one, Ramsey noted. Donors who find out their personal data was compromised may not give again. An organization that depends on sustained giving can lose its fundraising foundation and its donor community at the same time.

AI deepfakes and the threat boards aren't expecting

The cyber threat facing nonprofits has moved well beyond suspicious emails. Attackers can now replicate the voice and appearance of people inside the organization.

"With the fast-moving evolution of artificial intelligence, many cybercriminals are using sophisticated tactics that can even include audio and video deepfakes, where they might sound or look like someone affiliated with the organization that is being impacted," Ramsey said.

The risk is not theoretical. In 2024, engineering firm Arup lost US$25.6 million to a deepfake attack. A finance employee authorized 15 transfers on a video call where all other participants were AI-generated. IBM's 2026 Cost of Data Breach Report, meanwhile, found one in four malicious breaches last year were AI-enabled, up 56% year over year.

"When a nonprofit suffers a cyber event, costs are incurred with recovering from the attack, but it could also jeopardize the future of the organization if donors determine that their personal financial information is at risk," Ramsey said.

Nonprofits run leaner operations and maintain closer personal relationships with donors and board members. An attack timed to a pledge drive can stop fundraising at the most damaging moment of the year. 

"The reputational damage can be just as difficult to deal with, especially if the attack leads to business interruption," Ramsey said.

Making cyber a board-level conversation

Board buy-in on cyber investment is one of the more persistent challenges in nonprofit risk management. Most boards don't doubt that cyber risk exists. The harder task, Ramsey argued, is connecting it to a business consequence they can actually visualize.

"One cyberattack can put a company or a nonprofit out of business or disrupt it at the worst possible time - during an annual pledge drive, for example - if they haven't taken the necessary precautions," she said.

Boards don't respond to threat levels. They respond to business scenarios. Abstract cyber risk statistics rarely move a board that hasn't experienced an incident, Ramsey noted. Boards respond better to scenarios that threaten what they care about most.

"If they need more convincing, sharing examples of incidents involving other nonprofits and the impact it had can help paint the picture of cyber being a risk that can't be ignored," she said. 

Ramsey's approach translates directly for risk managers. Lead with what the organization would lose, not what an attack would cost to fix. Peer examples from comparable nonprofits can move the board when data alone doesn't.

A baseline that doesn't require a large IT budget

Many nonprofit leaders assume a meaningful cyber program requires a dedicated IT team and a large technology budget. That assumption keeps many organizations exposed. A functional cyber baseline is within reach for nonprofits of any size.

"Basic cyber hygiene is available to any nonprofit at little to no cost," Ramsey said.

The controls she outlines are specific and accessible. Strong passwords, updated systems, regular data backups, and multifactor authentication for email and remote access form the core. Staff training on how to recognize cyber threats rounds out the baseline, and most of these steps can be implemented without specialized technical knowledge.

Beyond basic hygiene, Ramsey recommends an incident response plan, a business continuity plan, and security requirements for vendors handling financial data. The incident response plan identifies who to contact the moment an attack is detected. The business continuity plan covers how operations continue while systems are down.

"Securing a stand-alone cyber insurance policy is also encouraged, as cyber exposures typically fall outside the scope of traditional insurance coverages," Ramsey said. "Many cyber insurance carriers provide risk service resources to assist organizations with these steps, along with training tools to help staff spot social engineering scams."

When an attack hits, minutes matter

A strong cyber hygiene baseline reduces the risk of a breach. What an organization does in the first minutes after detecting one shapes how far the damage spreads. Containing a cyber event quickly limits financial loss, operational disruption, and the reputational fallout that follows.

"When a cyber event takes place, minutes matter," Ramsey said. "Knowing whom to contact immediately after a cyberattack is detected - a board member, an incident response provider, an insurance carrier - can make a big difference."

The contacts list addresses what happens after an attack reaches the network. Employee training addresses how often it gets that far. Ramsey said the two steps are connected. Both are decisions the organization has to make before an attack arrives.

"If the attack was due to phishing or social engineering, organizations might look back with regret on the decision to not train employees on how to identify such scams," Ramsey said.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!