Nonprofit organizations hold three things attackers want: personal data, money, and easy access. Understanding what they are after helps you know where to focus your defenses.
Donor Data Has a Street Value
Donor records contain names, addresses, email addresses, phone numbers, and in many cases credit card or bank account details. On criminal markets, a complete donor profile sells for $20 to $150 depending on the donor’s financial history.
A nonprofit with 10,000 donors in its database is holding between $200,000 and $1.5 million in market value for attackers. They know this. They look for it specifically.
Grant Accounts Are a Direct Path to Cash
Most nonprofits receive wire transfers from foundations, government agencies, and corporate partners. Attackers who gain access to email accounts intercept these transfers by sending fraudulent banking change requests to the payer.
This attack is called business email compromise. The FBI reported $2.9 billion in BEC losses in the U.S. in 2023. In 2025, that number rose further. The 2026 figures are not fully reported yet, but every trend line points up. Nonprofits are easy targets for this attack because grant processes involve multiple people and informal communication chains.
Open Networks Make Entry Easy
71% of nonprofits allow staff and volunteers to use personal, unsecured devices on organizational networks. A volunteer’s personal laptop, running outdated software, connects to the same network storing donor records and financial data.
Attackers do not need a sophisticated vulnerability. They send a phishing email to a volunteer’s personal inbox. The volunteer clicks it on the same device connected to your network. The attacker is in.
Nation-State Actors Are in This Space Too
Microsoft’s Digital Defense Report lists nonprofits as the fourth most targeted sector by nation-state actors. Human rights organizations, advocacy groups, and international development nonprofits are targeted for intelligence gathering, disruption, and access to data about vulnerable populations.
In 2026, this threat is growing. Organizations working in politically sensitive areas face state-sponsored attacks alongside criminal ones.
Where to Start
Segment your network. Personal devices should not have access to donor databases or financial systems. Set up a separate guest network for volunteers. Most modern routers support this at no additional cost.
Require multi-factor authentication on all financial accounts and email systems. This one control blocks the majority of business email compromise attacks.
Get a security assessment to identify where your data lives and who has access to it. A fractional security consultant does this work at a cost most small nonprofits can absorb.

Leave a Reply