Court Rules
All enforcement actions
SettlementCritical RiskMultistate

State AGs Reach $49.5M Settlement with Blackbaud Over Data Breach

BlackbaudOctober 5, 2023New Jersey Attorney General

Penalty Amount

$49,500,000

Summary

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

Remedy

Blackbaud must pay $49.5 million to the states, implement and maintain incident response plans, provide assistance to customers for breach notifications, enhance cybersecurity training and resources, implement total database encryption and dark web monitoring, meet specific security requirements, and undergo third-party assessments for seven years.

Monetary PenaltyConsent DecreeAudit RequirementCompliance ProgramReporting Requirements

Laws Cited

state consumer protection lawsstate breach notification lawsHIPAA

Violation Types

Entity Details

Entity

Blackbaud

Industry

Technology

Multistate Coalition

Official Sources

Related Enforcement Actions

CA

Blackbaud

$6.8M

Blackbaud, a software company, suffered a data breach in 2020 due to inadequate security measures and made misleading statements about the breach and its security practices. California Attorney General Rob Bonta secured a $6.75 million settlement requiring Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

NY

Blackbaud

$49.5M

Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.

NJ

Susaida Nazario

A former employee of the New Jersey Department of Children and Families was indicted for allegedly leaking confidential child protection case information in exchange for bribes. The defendant, Susaida Nazario, misused her access to provide case details to an unauthorized individual, compromising sensitive children's data.

NJ

Uber Technologies, LLC, and Uber USA, LLC

New Jersey Attorney General Matthew Platkin announced that New Jersey is joining a coalition of 22 states in suing Uber for deceptive practices related to its Uber One subscription service. The lawsuit alleges that Uber enrolled consumers without their knowledge and made cancellation extremely difficult, seeking restitution, penalties, and an injunction under New Jersey's Consumer Fraud Act and the Restore Online Shoppers' Confidence Act.

NJ

Anthropic, Apple, Chai AI, Character Technologies, Google, Luka, Meta, Microsoft, Nomi AI, OpenAI, Perplexity AI, Replika, and xAI

New Jersey Attorney General Matthew Platkin is leading a bipartisan coalition of 42 attorneys general in sending a letter to 13 tech companies, demanding that they implement safeguards for their AI chatbots to prevent harmful interactions such as sexually explicit conversations with children, encouraging self-harm, and spurring violence, following reports of serious incidents including deaths and self-harm.

NJ

auto dealerships

The New Jersey Division of Consumer Affairs sent warning letters to over 3,000 auto dealerships reminding them of the state's data deletion law, which requires dealerships to offer to delete personal data from vehicles when accepting them for resale or lease. Failure to comply can result in fines of $500 for first offenses and $1,000 for subsequent offenses, aimed at preventing unauthorized access to sensitive consumer information stored in vehicle infotainment systems.