Skip to main content

Cybersecurity

Cybersecurity threats to non-profits

Cybersecurity threats to non-profits

Summary: Cyber threats to non-profits are common, often automated, and costly. This article explains why the sector is vulnerable and how organizations can reduce their exposure.

Non-profit organizations often handle sensitive information every day: from donor payment details and beneficiary records to employee data and grant documents. Many operate with limited budgets, small IT teams, and dependence on volunteers and third-party vendors. With that combination, non-profits become attractive targets for cybercriminals and, in some cases, politically motivated attackers.

Common cybersecurity threats to non-profits include phishing and business email compromise, ransomware attacks, cloud account takeover, exploitation of unpatched systems, and third-party vendor compromise.

The UK government’s Cyber Security Breaches Survey found that 28% of registered charities, an estimated 57,000 organizations, identified a cyber breach or attack in the previous 12 months. Among higher-income charities, the figure reached 57%.

Meanwhile, Cloudflare’s analysis of nearly 30 million emails from civil society organizations in 2026 found that nearly 10% were potential phishing attempts.

Cyber threats against non-profits are frequent, often automated, and rarely limited to large or well-known organizations.

Why non-profits are vulnerable to cyberattacks

Non-profits face many of the same cybersecurity risks as commercial businesses, but their operating conditions create specific weaknesses.

First, limited budgets and expertise. Most non-profits prioritize program delivery over IT spending. Only 17% of UK charities provided cybersecurity training to staff or volunteers in the past year. Among lower-income charities, the number dropped to 13%. Only 19% of surveyed organizations had formal incident-response plans.

Second, high turnover and volunteer access. Staff and volunteers join and leave frequently, sometimes without a formal offboarding process. Only 35% of UK charities restricted work to organization-owned devices, and just 28% monitored user activity. Shared accounts, leftover credentials, and personal devices all expand the attack surface.

Dependence on third-party vendors. Non-profits often rely on external CRM platforms, donation processors, payroll services, cloud hosting, and email marketing tools. But despite this dependence, only 9% of UK charities formally reviewed cyber risks associated with their immediate suppliers.

Publicly available information. Non-profits often publish their staff names, trustee details, and campaign calendars online. Attackers can easily use this information to write convincing phishing messages or impersonate a chief executive requesting an urgent bank transfer.

Finally, consequences beyond money. A cyberattack against a charity can affect vulnerable people, interrupt services, and damage trust in the organization. For non-profits working with refugees, domestic violence survivors, or political dissidents, a data breach can create direct physical risk.

Key cybersecurity threats facing non-profits

The threats below are the ones non-profits encounter most often, and understanding how each one works is the first step toward reducing exposure.

1. Phishing and business email compromise

Phishing remains the most commonly reported attack method. In the UK survey, 25% of all charities identified phishing attempts, and 69% of those that experienced an attack said phishing was the most disruptive incident.

Business email compromise (BEC) is also a type of phishing, but a step further. Hackers may compromise a real email account or create a convincing imitation, study previous conversations, and then request a payment, payroll change, or alteration to supplier bank details. In 2025, the FBI received 24,768 BEC complaints, which were associated with approximately $3 billion in reported losses across all US organizations.

2. Ransomware and data theft

A ransomware attack can encrypt files, disable systems, and halt operations. Modern ransomware often involves data theft as well. Mandiant found confirmed or suspected data theft in 77% of the ransomware intrusions it investigated in 2025, up from 57% the year before.

For non-profits, stolen files might include shelter locations, medical records, donor financial data, or the identities of activists and whistleblowers. What’s worse, attackers may threaten to publish this information to increase pressure for payment.

3. Cloud account takeover

Many non-profits store emails, donor records, financial workflows, and shared documents in cloud services. Hackers target these accounts through stolen credentials, session cookie theft, and voice phishing calls to help desks. A compromised cloud account can expose contact lists, payroll information, legal documents, and backups.

4. Exploitation of unpatched systems

For the 6th consecutive year, vulnerability exploitation is the most commonly identified initial access method. It’s simple: automated scanners search the internet for outdated software, vulnerable plugins, and misconfigured services.

A non-profit does not need to be individually selected by hackers to become a victim. Its outdated website or forgotten campaign page may simply appear in scan results. Cloudflare found that civil society websites experienced attempted vulnerability exploitation at a rate more than 7 times higher than that recorded across its wider customer base.

5. Third-party and supply-chain compromise

One vendor breach can affect thousands of organizations at once. Non-profits that outsource IT, payment processing, donor management, or payroll to external providers inherit those providers’ cybersecurity risks. With only 9% of UK charities reviewing supplier cyber risk, most organizations have little visibility into how well their vendors protect shared data.

6. DDoS attacks on public communications

Distributed denial-of-service (DDoS) attacks flood a website with traffic until it becomes unreachable. For non-profits, this can mean lost donations during a campaign, interrupted access to human-rights resources, or silenced journalism. Cloudflare’s 2026 data showed that DDoS accounted for 81.7% of all malicious traffic recorded against the civil society organizations in its sample, and some attacks lasted for days.

Feeling attacked? NordLayer’s got your back(wall) covered against DDoS disruptions

Protect your business from disruptive cyber-attacks

mob

Real-world examples of cyberattacks on non-profits

The following incidents show how the threats play out in practice. Each affected victim was a different kind of non-profit, but all 3 attacks disrupted services, exposed sensitive data, and carried costs that went well beyond a technical fix.

Ascension healthcare cyberattack (2024)

In May 2024, Ascension, one of the largest non-profit Catholic health systems in the US, detected a cyberattack that took down parts of its network. Electronic health records, the MyChart patient portal, phones, and test-ordering systems went offline at hospitals across several states. Some facilities diverted ambulances, postponed tests and procedures, and returned to paper records, so the attack affected patient care directly.

Ascension later reported that files with patient and employee information were stolen, with about 5.6 million people affected. It restored electronic health record access across its system within roughly 6 weeks, though later financial reports still recorded an operational and financial impact from the incident.

Internet Archive data breach and DDoS attacks (2024)

In October 2024, the Internet Archive, a non-profit digital library, faced a data breach along with website defacement and repeated denial-of-service attacks. The stolen login database held roughly 31 million unique email addresses, usernames, password-change dates, and hashed passwords. The organization took its services offline, so the Wayback Machine, Open Library, and other tools were unavailable or restricted while staff rebuilt the systems.

After the initial breach, hackers also misused a third-party helpdesk system to send unauthorized emails to users. The Internet Archive said its preserved collections stayed safe, and services returned gradually in read-only or limited form.

Radix Foundation ransomware attack (2025)

In June 2025, Radix, a Swiss health-promotion non-profit, reported a ransomware attack in which criminals stole and encrypted data, then published the stolen material on the dark web. Because Radix delivered services to several Swiss federal offices, some exposed files held information linked to parts of the Federal Administration. Switzerland’s National Cyber Security Centre said the attackers did not reach federal government systems directly, since Radix had no such access. The case shows how an attack on a non-profit service provider can expose client information, even when the clients’ own networks stay secure.

Best practices to protect your non-profit

Successful attacks often rely on gaps that are inexpensive to close, such as weak login protection, unpatched systems, or vendors no one has reviewed. You do not need a large budget or a dedicated security team to make progress. The steps below focus on the controls that reduce the most risk for the least effort, so a small team can start protecting sensitive information right away.

  1. Require multi-factor authentication (MFA) for all email, finance, CRM, cloud administration, and password manager accounts. Phishing-resistant options like hardware security keys or passkeys offer the strongest protection.
  2. Remove inactive accounts promptly. Revoke access as soon as a staff member, volunteer, or contractor leaves. Audit active accounts regularly.
  3. Patch internet-facing systems quickly. Maintain an inventory of websites, applications, and domains. Remove unsupported software and decommission abandoned campaign sites.
  4. Keep offline or immutable backups. Test restoration regularly. Protect backup administrator accounts separately from everyday network credentials.
  5. Review vendor security. Identify which suppliers hold your data, what controls they have in place, and what their incident-notification terms look like.
  6. Train everyone. This includes trustees, employees, volunteers, and temporary staff. Cover payment fraud, MFA-reset scams, telephone impersonation, and how to report mistakes quickly.
  7. Create an incident response plan with real names and contact details. Only 19% of UK charities had a formal plan. Your plan should identify the incident lead, technical provider, legal advisor, insurer, board contact, and relevant regulators.

A non-profit doesn’t have to apply all of these at once. Start with multi-factor authentication and account cleanup, since they block the most common attack routes, and then work through the rest as time and budget allow.

How to respond to a cybersecurity incident

The first hours of an incident shape how much damage it causes. These 5 steps cover the actions that most affect the outcome. If you suspect a breach, work through them in order.

  1. Contain the problem. Isolate the affected system or account and notify your incident lead.
  2. Preserve evidence. Avoid wiping or rebuilding systems before you capture logs and other records. The evidence helps you understand what happened and may be required for legal or insurance purposes.
  3. Bring in expert help before going public. Contact your IT provider and legal advisor first.
  4. Check your notification duties. In the US, requirements vary by state and data type, so confirm what applies to you. In the UK, organizations generally must report qualifying personal data breaches to the Information Commissioner’s Office (ICO) within 72 hours.
  5. Document every step. Record each decision and action taken during the response. Good records support regulatory reporting, insurance claims, and any review you carry out afterward.

Stronger cybersecurity for nonprofits with NordLayer

Nonprofit organizations need security tools that are simple to deploy, affordable to maintain, and effective without a large in-house IT team. NordLayer supports cybersecurity for non-profits with network access security features that directly address the threats non-profits face.

From secure remote access and network segmentation to centralized access controls and threat protection, the NordLayer platform helps non-profits protect sensitive information, reduce exposure to security breaches, and meet their data security responsibilities without overloading their budget or their staff.

Cybersecurity Copywriter

Share this post

Related Articles

Stay in the know

Subscribe to our blog updates for in-depth perspectives on cybersecurity.