ListedTech
  • Data Portals
    • Portal for Industry
    • Portal for Institutions
    • Webinars
  • Product Categories & Reports
  • Resources
    • Blog
    • Podcast
    • Documentation
    • Webinars
  • About Us
    • Our Story
    • Data Overview
    • Traditional IT Research vs. ListEdTech
    • In the Media
    • Contact Us

Search the website...

Go to Portal
Posted on September 13, 2020 | by Justin Ménard

Cyber Attack Towards Blackbaud: Class Actions Have Been Filed

Conferencing Learning Management Systems Retention
Blackbaud HigherEd Educational Clients Gain and Loss - LisTedTECH

Over the course of May, June, and July 2020, Blackbaud suffered a ransomware cyber-attack. At this time, the hacker was able to access personal information in the company database: names, titles, gender, dates of birth, student numbers, addresses, phone numbers, email addresses as well as LinkedIn profile URLs. From what the company has said, the breach was quickly contained, but the damage was done. 

When Blackbaud decided to disclose the attack in July and August, they were then blamed by their clients (universities, health companies as well as non-profit organizations) for the “heightened risk of identity theft and fraud due to Blackbaud’s ‘negligent conduct’ with regard to safeguarding the sensitive information of thousands of students, patients, doctors, and donors.” (Allen v. Blackbaud). 

More recently, I have learned that, in some cases, the hacker was able to obtain partial credit card numbers. Universities are unsatisfied with the way Blackbaud minimized this aspect of the cyber-attack.

One of my professional connections mentioned that his university reached out to their legal firm to see if a partial credit card number constitutes a breach. From the different conversations between Blackbaud and its clients, Blackbaud never seemed to define partial credit card numbers as credit card information. Another contact even pointed out a possible phishing situation where a malicious person could send a text to one alumni/donor asking to update their credit card information on the XYZ e-commerce website.

In addition to the class action filed on August 12, 2020, by Allen, another one (Johnson v. Blackbaud) has been brought to the media attention on September 4, 2020. Both class actions mention that the company neglected to properly store personal information on its computer network. Among the requisitions from Johnson (p. 4), one is that Blackbaud needs to adopt reasonably sufficient security practices to safeguard the personal information that remains in its custody in order to prevent incidents like the data breach from reoccurring in the future.

On its website, Blackbaud created a page on the ‘security’ incident. The vocabulary used tries to minimize the situation and shows how the company has invested in professional security personnel within the last five years. A question many may ask is: why did the data breach happen if this team was at work trying to avoid this kind of attack?

The graph above shows the number of new clients in green and the number of clients lost in red. As you can see, Blackbaud has had a positive relationship with its customers and gained over time more customers than it lost. The only exception is the year 2020. Since 2020 is… 2020, I can’t explain if this is due to the data breach or it is simply because several selection committees have been stopped or even that resources have simply been reallocated.

At the moment, I don’t know exactly how this security breach will impact Blackbaud in the future, especially with regards to maintaining its client base or attracting new clients. Some institutions have been asking if other solutions can be used in place of Blackbaud; but since they are still under contracts with Blackbaud, these alternatives will have to wait. One thing is certain, these class actions may impact the perception clients have on how Blackbaud reacts in a security crisis.

Post navigation

Has Turnitin Found its Competition in the New Company Ouriginal?
System Lifespan: HigherEd Institutions Are Keeping Their Systems Longer
  • Subscribe to Our Newsletter
  • CAPTCHA image

    * All fields are required.

  • Listen to Our Podcast


  • Recent Posts

    • Who Are HigherEd’s Tech Leaders? October 15, 2025
    • Anthology’s Chapter 11 Filing: Breaking Up to Refocus October 1, 2025
    • Rethinking Market Saturation in EdTech September 24, 2025
    • Thesis: From Unit4 Spin‑Off to SIS Specialist September 17, 2025
    • How Institutions Discover What Tech Their Peers Are Using September 3, 2025

Stay in the know…

Blog & News
Higher Ed Market Data

Who Are HigherEd’s Tech Leaders?

This year, I’ve been revisiting some of the classic business books: Blue Ocean Shift, Free, The Innovator’s Dilemma, Zero to One, and of course, Crossing the Chasm. That last one really got me thinking about early adopters. In tech markets, they’re the people (or in HigherEd, the institutions) who are comfortable taking risks, trying something new, and shaping the market ... Who Are HigherEd’s Tech Leaders?  Read More
Market Data Market Movements

Anthology’s Chapter 11 Filing: Breaking Up to Refocus

September 2025 marked a major turning point for Anthology, the owner of Blackboard and several other higher education technology platforms. The company filed for Chapter 11 bankruptcy in the U.S. after efforts to sell itself or parts of its business outside of court failed. The filing is not a liquidation. Instead, it is a structured reorganization designed to ... Anthology’s Chapter 11 Filing: Breaking Up to Refocus  Read More
ListEdTech Market Data

Rethinking Market Saturation in EdTech

Market saturation is a concept we often discuss at ListEdTech because it comes up frequently with our clients. Investors want to know if a market still has room to grow, while startups want to understand whether they are entering a space with opportunities or one that is already crowded. Last year, we explored saturation by ... Rethinking Market Saturation in EdTech  Read More
Footer Logo - LisTedTECH
  • Contact Us
  • Frequently Asked Questions
  • Privacy Policy
  • Terms of Use