/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The FTC settles with Blackbaud, ordering the cloud software company to delete consumers' data and boost security after a May 2020 data breach affected millions

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Blackbaud’s 2020 incident has already produced a SEC settlement over breach disclosures and a multistate attorneys general settlement. The FTC action adds a consumer-data remedy to an enforcement trail that had focused on disclosure and state-level investigation.

The case matters because it ties breach remediation to the data a company continues to hold, not only to a monetary payment or public account of the incident.

First-order effects

  • Blackbaud must delete affected consumers’ data and strengthen its security practices, making data handling and security controls an immediate compliance obligation.
  • The FTC extends the consequences of the 2020 breach beyond Blackbaud’s prior SEC and state settlements, increasing the company’s remediation burden.

Second-order effects

  • Cloud software providers handling sensitive customer records may face stronger pressure to document retention, deletion, and security processes after an incident.
  • Customers of vendors that centralize constituent or consumer data may give greater weight to post-breach remediation commitments, alongside disclosure practices.

Third-order effects

  • If this enforcement pattern persists, breach settlements may increasingly combine financial penalties with operational mandates governing how firms retain, delete, and protect personal data.
  • The cumulative Blackbaud actions suggest that a single cyber incident can trigger parallel scrutiny from securities, state, and consumer-protection authorities, raising the value of coordinated incident response.

The trend: Cybersecurity enforcement is shifting from one-time breach penalties toward sustained requirements for data governance, remediation, and security controls.

Discussion

  • @ftc @ftc on x
    FTC says company's poor security allowed hacker to steal sensitive data of millions of consumers, go undetected for months /2
  • @suzannemsmalley Suzanne Smalley on x
    FTC settles w/ Blackbaud for sprawling data breach exposing sensitive financial, health, other data belonging to millions of consumers, including schoolchildren. Agency says Blackbaud data practices were shoddy + that it lied to customers abt scope of hack https://therecord.media…
  • @ftc @ftc on x
    FTC order will require Blackbaud to delete unnecessary data, boost safeguards to settle charges its lax security practices led to data breach: https://www.ftc.gov/... /1
  • @anaelisafoto Ana Fuentes on x
    “In addition to failing to encrypt sensitive data and implement adequate firewalls to help protect it, Blackbaud held onto data far longer than was necessary for the purpose for which it was maintained, incl information belonging to former customers, according to the complaint.”
  • @skye_witley Skye Witley on x
    NEW: Software maker stored personal data years too long, per FTC complaint. A proposed settlement makes “clear that maintaining a data retention and deletion schedule is a critical part of protecting consumers' data security,” agency officials said. More: https://news.bloombergla…
  • @swiftstories Mike Swift on x
    In another @FTC order requiring a company to delete data, @blackbaud must delete PII and boost safeguards due to “shoddy” #datasecurity https://www.ftc.gov/...