AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / The data you hold

The data you hold

The Donor File Is Your Most Sensitive Record, and It Is Wide Open Until Thursday

Nonprofit donor data security before the year-end appeal: what sits in the CRM, who can reach it, and the six checks a Washington DC nonprofit makes first.

Sam KhanSam Khan The Cyber ExpertFounder and CEONovember 9, 2026 · 6 min read

Two weeks before the year-end appeal

The development director of a 22-person advocacy organization two blocks off Dupont Circle is building the year-end appeal file on a Thursday afternoon. Eleven thousand donors, sorted by giving history, with a separate segment for the 140 people who might give five figures if the executive director calls them personally.

She exports it to a spreadsheet, because the mail house wants a spreadsheet, and drops it in a shared drive folder that a consultant set up during the spring campaign. The folder is set to anyone with the link. It has been that way since April.

The file has columns nobody thinks about until they are read aloud. Home addresses. Employer. Spouse. Bank routing details for the 600 monthly sustainers. And the notes field, where a program officer wrote, in the candid shorthand development teams use, that a donor's giving dropped after a divorce and that another is expected to fund a program in memory of her late husband.

The consultant's own email account was compromised in October. Nobody at the nonprofit knew: her engagement ended in June and her access never did.

The appeal goes out on the first Tuesday of December. Three weeks later a donor calls to ask why she got an email, from an address one letter off the executive director's, referencing the gift she made in memory of her husband, and asking her to wire it to a new account this time.

What the heck does this mean

Donor data is a category of its own. It behaves like customer data, employee data and health data at the same time, which is why the standard advice for a small business does not fully cover it.

Constituent relationship management system, the CRM: the database that holds every donor, gift, pledge and interaction. It is the single most valuable asset most nonprofits own, and it is rarely treated that way.

Anyone with the link: a sharing setting that turns a file into a public web page for anybody who ever receives, forwards or finds that address. Search engines and browser extensions find them.

Vendor access: the consultants, mail houses, agencies and volunteer database managers who need a login for a season and keep it for years. In your CRM they are usually indistinguishable from staff.

Impersonation of the executive director: an attacker with a copy of your donor file knows names, giving amounts and the story behind the gift. That is enough to write an email your donor believes, and to ask for money in the same voice you use.

The reason this stings for a nonprofit is not the cost of the incident. It is that trust is the product. A donor who learns their circumstances were in a spreadsheet on the open internet does not send a complaint. They stop giving, and they tell two people.

The numbers that matter

Third parties were involved in 48% of breaches in the Verizon 2026 Data Breach Investigations Report, an increase of 60% over the prior year. For an organization that runs its appeal through consultants and a mail house, that is the most relevant statistic in the report.

Business email compromise accounted for USD 3.05 billion in reported losses across 24,768 complaints in the FBI IC3 2025 Internet Crime Report, with 86% of the funds moved by wire or ACH. A redirected major gift arrives inside that number, and so does a redirected grant payment.

Ransomware featured in 88% of breaches at small and medium organizations in the Verizon 2026 DBIR. A nonprofit with an encrypted CRM in the second week of December has lost the appeal, not just the week.

What to do this week

  1. Open your shared drive and filter for files shared with anyone with the link. Every export, every mail merge, every board packet. Turn the setting off, then set exports to expire so it does not rebuild by April. (CIS 3 Data Protection)
  2. Pull the user list from your CRM and read it out loud with the executive director. Former staff, the spring consultant, the volunteer who built the reports in 2023, the intern. Remove everyone who does not have a reason today, and give the ones who remain their own named account. (CIS 6 Access Control Management)
  3. Turn on multi-factor authentication for the CRM, email, the payment processor and the online giving page, starting with the four people who can export the full donor list. Those four accounts are the appeal. (CIS 6 Access Control Management)
  4. Write the gift verification rule and tell your major donors about it in the appeal letter: this organization will never change its bank details by email, and any request to do so should be confirmed by calling the office number on the website. A rule your donors know about protects them from an email you never sent. (CIS 3 Data Protection)
  5. Put two clauses in the mail house and consultant agreements before the appeal drops: named individual accounts with an end date, and written notice to you within 72 hours of any incident that touches your data. (CIS 15 Service Provider Management)
  6. Test a restore of the CRM from a backup that is not connected to your network, note how long it took, and put that note in the board file. December is the wrong month to discover the answer. (CIS 11 Data Recovery)

Where AccuSights fits

Small teams with big files are our normal work. Our assessment shows where donor records actually live, which is usually four places nobody listed, who can reach them, and which vendor holds a copy. You get a ranked plan sized for a staff of 22, not a 90-page report. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of the systems that run the appeal, and we work with nonprofits across the District, Maryland and Northern Virginia. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.

Questions people ask

What donor information is actually sensitive? More than the mailing address. A donor record usually carries giving history, employer, household relationships, bank details for recurring gifts and the notes your team writes after a meeting, including capacity ratings and personal circumstances. The notes are the part that ends careers and relationships, because they were written for internal use in a candid tone and read like an insult on a screenshot. Treat the notes field with the same care as the ACH details.

Do consultants and agencies need their own logins to our CRM? Yes, their own named logins, with the access their role requires and an end date on the engagement. Shared accounts and passed-around passwords make it impossible to answer the only question that matters after an incident, which is who exported what and when. Put the named-account requirement and a breach notification clause in the contract before the appeal season starts, and switch the accounts off the week the engagement ends.

Does a nonprofit have to notify donors after a breach? In practice, usually yes. Every US state has a breach notification law and they apply to nonprofits, with the trigger set by the residency of the affected people rather than by where your office is, so a national donor list means multiple state rules at once. Twenty US state privacy laws are also in force in 2026 with their own obligations. Ask counsel early, and make sure someone can produce the exact list of records touched, because the size of the notice depends on that list.

You ask people to trust you with their money and their reasons. The file where you keep both deserves better than a link that has been open since April.

Controls this post maps to

CIS 3 Data ProtectionCIS 6 Access Control ManagementCIS 15 Service Provider Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.