/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cloud software company Blackbaud settles with the SEC for $3M over its “misleading disclosures” about a May 2020 ransomware attack that affected 13K+ customers

Carly Page / TechCrunch : Tweets: @agtoddrokita Tweets: Todd Rokita / @agtoddrokita : Glad to assist the SEC in getting this case settled. My office will always fight to ensure consumers are protected, particularly from devastating ransomware attacks. https://www.sec.gov/...

TechCrunch Carly Page

Context & Ripple Effects

Blackbaud, a cloud software vendor whose customer base is largely nonprofits, disclosed a May 2020 ransomware attack affecting more than 13,000 organizations — and the SEC's charge here is not the breach itself but what the company told investors about it. The $3M penalty lands on top of a widening enforcement pile: an earlier [[a:946189|Comscore settlement showed the SEC willing to penalize false statements by public companies]], while Activision Blizzard's $35M SEC deal signaled the agency pressing hard on disclosure-controls failures at operating companies.

First-order effects

  • Blackbaud pays $3M to the SEC for misleading disclosures about the 2020 ransomware attack, with state enforcers like Indiana AG Todd Rokita's office claiming credit for assisting — a direct reputational and financial hit layered onto the breach fallout already hitting its 13,000-plus affected customers.
  • Nonprofit customers of Blackbaud now have a federal record confirming the company understated the breach's scope in its disclosures, sharpening their leverage in contract negotiations and data-handling demands.

Second-order effects

Third-order effects

  • For cloud software vendors serving nonprofits, schools, and similar sectors, the pattern establishes that how a breach is disclosed — not just the breach — is independently punishable by securities regulators, states, and the FTC in sequence, making incident-response communications a board-level compliance function.
  • If the cascade model holds, breach costs stop being a single insurable event and become a multi-regulator sequence where each settlement cites the last, shifting vendors toward conservative, immediate full-scope disclosure as the cheapest long-run strategy.

The trend: Data-breach accountability is consolidating into stacked multi-regulator enforcement, where a single incident generates sequential SEC, state-AG, and FTC penalties against cloud software providers.

Discussion

  • @agtoddrokita Todd Rokita on x
    Glad to assist the SEC in getting this case settled. My office will always fight to ensure consumers are protected, particularly from devastating ransomware attacks. https://www.sec.gov/...