A Washington story
The Tuesday the donor file almost went out with the year-end appeal
the executive director of a 28-person association on Connecticut Avenue near Dupont Circle
It is a Tuesday in December, the second week of the year-end appeal, and the executive director has run the association for nine years. The donor file holds 41,000 names, giving histories and the notes that explain why a member in Reston gives every November and one in Bethesda never does. It is the association.
At 10:40 the finance manager gets an email from the audit firm's real domain, referencing the real engagement, asking her to view the draft management letter in a shared workspace. The link asks her to grant an app permission to read her mailbox and files so the letter can load. She does, because the audit is real and the letter is due.
The app is not the audit firm's. By 10:52 it is asking for the donor file.
The engineer sees the consent grant at 10:53, revokes it and calls. The finance manager gets a thank-you, not a lecture. The audit firm gets a call about the mailbox someone borrowed on their side. The appeal goes out Thursday, to 41,000 people who never find out how close it came.
The request dies at the door: bulk downloads from that library need a second approval, and nobody gave one.
What changes the ending
- The donor file in one protected library with bulk-download limits and a second approval, not on a shared drive next to the newsletter templates (CIS 3 Data Protection).
- Third-party app consent restricted to an allow list, so a "view the audit letter" click cannot hand a stranger your mailbox (CIS 4 Secure Configuration of Enterprise Assets and Software).
- Training that treats December as phishing season, scored per person, with a report button that reaches an engineer (CIS 14 Security Awareness and Skills Training).