Blackbaud hack: More UK universities confirm breach
bbc.com
bbc.com
On Thursday, 16 July, we were made aware of a security incident involving one of our third-party service providers, Blackbaud.
Blackbaud is one of the world's largest providers of customer relationship management systems for the higher education and not-for-profit sectors.
It informed us that in May it had discovered and stopped a ransomware attack on its systems, although some data was compromised. A number of universities using its services have been affected, including the University of Leeds.
The company assures us that data compromised in the incident was comparatively low risk and did not contain any password, bank account or credit card information.
We are continuing to work closely with Blackbaud to determine exactly what personal data was compromised. We understand that other clients of Blackbaud have been affected in different ways, with varying types of data involved. In our case, it appears that names and email addresses for some members of our alumni and supporter community were affected. Information on the sums given as gifts or event payments through the alumni web portal, Leeds Alumni Online, may also have been affected, although not any bank account or credit card details. As we understand that you haven’t used our website to make any financial transactions, this aspect will not affect you.
Blackbaud paid a ransom to the cybercriminal and received assurances that the stolen data was destroyed and not used or sold on to third parties. Blackbaud says that – based on the nature of the incident, its research, and investigation by third parties (including law enforcement) – it has no reason to believe any data went beyond the cybercriminal, was or will be misused, or will be disseminated or otherwise made available publicly.
They have a really corporate sense of humour.
If victims believed that a ransom wouldn't do anything they would not pay them as much.
I think there's a parallel with kidnapping in some countries, it's almost business like.
I fully expect this data to surface in a year or so.
Also have you never worked for a corporation? My first thought is that the management went for the first most obvious solution that is paying the money.
> We recently learned that Selwyn was one of a number of educational and voluntary sector organisations in Cambridge, the UK and across the world to have been affected by a data breach at the US company Blackbaud. [...] In order to protect customers’ data and mitigate potential identity theft, Blackbaud met the ransomware demand in relation to this file. Blackbaud has advised us that having paid the ransom it received assurances that this data had been destroyed and since then there has been no indication that this data remains in circulation.
They also linked to Blackbaud's statement, which confirms they paid the ransom:
> Because protecting our customers’ data is our top priority, we paid the cybercriminal’s demand with confirmation that the copy they removed had been destroyed.
Incidentally, the notification was sent via Blackbaud, and appears to track that I clicked through to the statement (URL includes bblinkid/bbemailid/bbejrid parameters).
https://www.selwynalumni.com/main-website-pages/blackbaud-da...
https://www.blackbaud.co.uk/newsroom/news-archives/2020/07/1...
I wonder how much information they still have on me, seeing as I graduated 18 years ago ...
In all candor, we are frustrated with the lack of information we've received from Blackbaud about this incident thus far. The ACLU is doing everything in our power to ascertain the full nature of the breach, and we are actively investigating the nature of the data that was involved, details of the incident, and Blackbaud's remediation plans.
We are also exploring all options to ensure this does not happen again, including revisiting our relationship with Blackbaud.
Our contract with them ends soon and we will definitely not be renewing when it’s up.
plus most places will need some time to put an alternative in place. it's commendable if anybody manages to convince management and does this though. inertia and i imagine blackbaud did provide significant value/functionality?
> On 16th July, Blackbaud informed us of a data security incident [...] they had been the victim of a ransomware attack between February and May 2020.
> Amongst the information that may been affected were the following[...]
> Blackbaud is unable to confirm precisely which individual records have been affected
https://www.selwynalumni.com/main-website-pages/blackbaud-da...
On the basis that A) Blackbaud did not inform it's customers promptly B) The vulnerability is potentially still out there so further data leaks can happen in the future
I think every single organisation using Raisers Edge needs to plan on a migration to a new system. A big and ugly task but I can't see how anyone would think it is responsible to keep their data stored with this organisation.
Not got a stake in it or anything but I work at a charity who use Microsoft D365 (which for charities is dirt cheap) and we are feeling very relieved that we did not decide to use Raisers Edge.
I have also received this from the University of York. The timescales in play here seem terrible from Blackbaud's discovery to initial report.
That’s going to keep happening until someone gets the book thrown at them for slow-walking a response. I know this is a pretty anti-regulatory crowd, but we can’t expect this behavior to change if there are no consequences.
How about an opt-in scoreboard or ratings system for responses, with some objective criteria?
Regulation would need to be based on objective criteria anyway, so why not develop them as an industry?
The credit rating agencies have some of the lowest consumer confidence scores in the entire country, and yet Equifax suffered no consequences from its massive breach a few years ago.
Also, your suggestion is opt-in. Why would any company volunteer themselves to be scrutinized in such a faux way?
But it doesn’t follow that all rating systems will be garbage for all time.
The rating system would not deter misbehavior. ‘Misbehavior’ in this case is just competence. The rating system would give clients some transparency into the competence of the service provider.
Any company that was confident in its processes would volunteer for scrutiny because it would be positive for their credibility, just like other independent certifications.
The question would then become - why would a customer choose an unrated company?
I think Raiser's Edge is used quite a bit in the sector, though I believe there are on-prem as well as cloud variants of the software?
A lot of charities use Raiser's Edge, I wonder if they are also affected?
Although that BBC report says
"One of the affected institutions told the BBC the hack is affecting a product called NetCommunity which Blackbaud describes on its website as an 'alumni engagement and management software system for nonprofits.'"
... so maybe Raiser's Edge was not part of the hack
Alumni tend to contribute either to leave a legacy behind or to help the College maintain it's reputation, which in turn helps the alum's reputation for having graduated from there.
Surely this can't work without some aultrism involved? I find it doubtful that any alumni can get 10k of benefit from the increased reputation that a 10k donation can provide.
Declining marginal utility, and how rich the people who tend to make big donations are, play a role here.
If you earn 50K, you net 37640. 51K and you get 38220.
If you earn 51K and donate 1K, you net exactly the same as if you just earned 50000. i.e. 580 less than if you had just kept it (If you had put it in your pension instead, you would have kept the whole 1000)
There may be some circumstances where it makes a difference, where certain thresholds could be crossed, but AFAIK, the way they all taper prevents that.
You can only get a tax break on 40K of pension contributions, so if you earn 91-101K and claim child benefit, without another pre-tax vehicle to soak up the rest, you'd have to pay the clawback charge. However, I doubt that would work. With 3 children you'd have to donate 10K to save about 2.5K.
If you earn something around 300K, it might do something because of the tapered pension allowance. Again, I doubt it. At 250K, if you donate 10K, you can put an extra 5K in your pension. Above that, I don't think there are any more thresholds.
A number of schemes exist around various countries to promote incentives to donate, and they typically end up with people paying less tax overall than they would otherwise. (Note: I don’t think it’s a bad thing, no critique meant).
In the illustration in your link, Sue gives 1k to charity, and as a result, and pays 350 less tax. This means that, as a result of this donation, her net income has fallen by 650.
I did not provide the specific names of all the rules, but I thought that would be obvious from the numbers, context, and some of the terms
I had not considered the difference between payroll giving (my first example,give 1k before tax, charity gets 1k, your taxable income is 1k less), and claiming back (you give 1k after tax, charity gets 1.25k, you reclaim some of the tax you paid), but payroll giving is more efficient for the donor, as they pay zero tax on the donation, rather than basic rate, as in the reclaim method.
There is no UK legislation, as far as I know, that reduces your tax bill by more than your donation.
The schemes amplify the effects of existing altruism, rather than offering incentives to persuade non-donors to donate.
Asking alumni for donations is done very frequently by non-profit private universities, which you're probably confusing for for-profit. Harvard is an example of such a university.
I don't know if for-profit schools also ask for donations, but those sort of schools are generally quite disreputable and frankly low class. An example is the now-defunct ITT Tech, which was best known for spamming cheap cable television ads.
Press release goes out, saying the data was "deleted"
Send another ransom, maybe 5 BTC, otherwise data is released
Insert taps on head meme
Imho it’s much better to just sit on it for a few months, then hit the usual forums to market it as high-quality data.
To a criminal that's easily worth an ask of 5BTC - or perhaps x% of annual profits in perpetuity.
An extortion scam is likely to be worth more than the data.
A prolonged extortion scheme can only be done on a low-scale highly-targeted basis, where you can ensure word doesn’t get out.
Most cryptolockers and other random criminals do exactly what they promise because if they don't, their business model will collapse. All of the stolen info isn't worth nearly as much as what universities are willing to pay out if you keep your promises.
It's wicked, but these criminals do have a business incentive to be nice. Their next target will probably pay again if they act smart.
The problem is that smart criminals don't directly attack a single corporation or university, they'll attack a SAAS/IAAS/PAAS provider many of their potential targets use and see what they can get out of the data. In this instance even one university paying out would probably be enough to offset the risk and cost of the criminal operation.
In many cases, paying out is also the economical choice to take, especially in ransomware attacks. Even if backups were made, tested and recent, paying a million here and there might still be worth it if not doing so would cost weeks or even months of work and employees and students lacking IT services. With modern education being run like a business, I'm not sure if it'd even make sense to bet on such a statement to be worth it. You may shoot yourself in the foot when you eventually do get hit and you need to either spend lots of time and money or break the promise you made on your website (betraying your employees and students in the process by showing that you cannot hold up the values you claim to have).
Presumably all competent scammers benefit from being able to repeat the scam, and would lose out if the scam stopped working, so they all have an incentive not to defect.
Scams like this depend on the scammers understanding the incentives better than their targets and so it’s reasonable to assume that the scammers are aware of the context.
However - this is probably true as well:
The victim (individual organization or SaaS provider) wants to just have it end.
The ransomer has the incentive to build the pattern of "pay the ransom and nobody gets hurt [in this incident]", because it builds the business model.
Cybersecurity insurance exacerbates the problem, because the insurer knows that payouts solve the incident for the insured at a relatively low cost, and that each incident perversely increases the need organizations have for the insurance.
Conversely, if no one pays ransoms, it immediately ceases being a viable criminal business model.
And yes, you are correct, organisations have 72 hours to disclose the breach.
The various data protection offices (such as the ICO in the UK) usually try to work with organisations first. If Blackbaud aren't playing ball though, they may be in for a rough ride (assuming that they actually operate where the EU has jurisdiction that is).
A data controller has 72 hours to notify the ICO (or other supervisory authority). A data processor has no such obligation [unless specified as part of the data processing agreement DPA]
Most DPA will state asap s.t the controller can notify
But in this instance Blackbaud would almost certainly be a processor
(It’s a neat [nasty] little loophole
For more reading on this:
https://ico.org.uk/for-organisations/guide-to-data-protectio...
Note: I am An admin that administers part of their product suite, that has mostly not been affected to my Knowledge because we are mostly using heir products on-prem
1. This isn’t a ransomware attack in the traditional sense. They had an intrusion starting in February that they noticed in May because the actor was sending data offsite. They then held that data for ransom. That’s not ransomware, that’s getting hacked.
2. They will not tell people what specific data was exposed. Only “internal systems”. That may include things like customers that have on prem solutions but have to send backups of their DB for support etc. BLackbaud won’t say anything.
3. There is no way to confirm the malicious actors didn’t have copies of their own data that wasn’t deleted. It got out of their control and they lost all chain of custody. They are literally trusting criminals here as a way to say it’s not exposed (and hiring some firm to “monitor the dark web” for data)
4. While some data is encrypted, hows it’s encrypted in at least a few cases I know of isn’t exactly secure. For example in one product the encryption key is stored in a stored procedure packaged into their compiled installer and is placed into an ssis package on any sql instance the product is installed. It’s the same key for all customers (and I’ll just say isn’t randomized or very hard to iterate). If the actors got any access to their installers, all they would have to do is join the database to the installer and boom, encryption is useless.