Michigan Attorney General Dana Nessel issued a consumer alert last Friday telling Michigan residents, particularly college and other nonprofit donors, to beware of fraudulent emails and phone calls seeking personal information or suspicious donation requests.
The alert follows a ransomware attack on Blackbaud, a major provider of software services used by nonprofits in fundraising that resulted in the acquisition of donor information by a cybercriminal. Blackbaud customers include colleges, hospitals, churches, and various other types of nonprofits throughout the U.S., including in Michigan. Some Michigan entities include Michigan State University, Lansing Community College, the Catholic Diocese of Gaylord, John Ball Zoo, and others.
Blackbaud notified affected customers using its services of the security breach, leaving it to those nonprofits to provide any notice to impacted individuals. The breach was reported by Blackbaud in mid-July.
The Blackbaud security breach and its impacts on nonprofits and consumers vary. Social Security numbers, credit card and bank account information were not accessed, according to Blackbaud. Accessed information generally included names, titles, telephone numbers, email addresses, mailing addresses, dates of birth and, more importantly, donor information such as donation dates, donation amounts, giving capacity, philanthropic interests and other donor profile information. Blackbaud claims that it has “no reason to believe that any data went beyond the cybercriminal, was or will be misused; or will be disseminated or otherwise made available publicly” but, to date, has not announced any concrete substantiation of this claim.
“Donor information can be a roadmap identifying people willing and able to contribute to worthy causes and institutions. In the wrong hands, it can target individuals for exploitation and scammers,” said Nessel. “Personal information with this level of detail, in the hands of fraudsters, is particularly susceptible to spear phishing – a fraudulent email to specific targets while purporting to be a trusted sender, with the aim of convincing victims to hand over information or money or infecting devices with malware. Anyone who receives a notification letter regarding the Blackbaud data breach should not dismiss the letter, and should not only take the recommended steps in the notice, but also remain vigilant for suspicious emails, texts or phone calls asking for personal information, donations or other payments.”
Nessel urges every Michigan resident who gets a text, email, or call that is supposedly from an organization or business asking for login credentials, credit card, bank account or any other personal information to hang up and not respond.
“The bottom line is this: Don’t give a single piece of personal information – your birth date, the last four digits of your Social Security number, your PIN numbers – to anyone who calls,” Nessel said. “Hang up the phone and call back to a number you know to be legitimate.”
Consumers are encouraged to file consumer complaints with the Michigan Department of Attorney General online (www.michigan.gov/ag) or by calling 1-877-765-8388.
- Posted September 21, 2020
- Tweet This | Share on Facebook
Consumers reminded to watch for phishing scams following Blackbaud security breach
headlines Oakland County
headlines National
- ABA Legislative Priorities Survey helps members set the agenda
- ACLU and BigLaw firm use ‘Orange is the New Black’ in hashtag effort to promote NY jail reform
- Judge gave ‘reasonable impression’ she was letting immigrant evade ICE, ethics charges say
- 2 federal judges have changed their minds about senior status; will 2 appeals judges follow suit?
- Biden should pardon Trump, as well as Trump’s enemies, says Watergate figure John Dean
- Horse-loving lawyer left the law to help run a Colorado ranch