No nonprofit is immune from a cybersecurity breach. In fact, Denver organizations can gain important nonprofit cybersecurity lessons from a data breach that affected a nonprofit organization in New York. This New York-based nonprofit discovered suspicious activity in its network in January 2026. The incident potentially exposed health, financial, employee, and client information belonging to approximately 90,000 people.
Although the organization operates in New York, the risks should feel familiar to nonprofits across Denver. Organizations that provide behavioral health, workforce development, housing assistance, and community services depend on technology to support people. They also collect information that criminals can use for fraud, extortion, phishing, or identity theft. Cybersecurity therefore affects more than computers. It affects whether people trust an organization enough to ask for help.
A Nonprofit Cybersecurity Warning for Mission-Driven Organizations
The breached nonprofit organization provides healthcare and employment services to underserved New Yorkers. This particular organization helps more than 35,000 people each year access healthcare, employment, and community resources.
On January 10, 2026, the organization identified suspicious activity within its network. It secured the environment and began an investigation with outside cybersecurity professionals. On January 27, the organization determined that the incident may have affected protected health information and other personal information.
In March, Comparitech reported that the Genesis ransomware group had claimed responsibility for the attack. The group said it stole 2 TB of information, including medical and human resources files. However, Comparitech noted the organization had not confirmed the claim and that the publication could not independently verify it. Comparitech later reported that approximately 90,000 people had been affected.
The nonprofit has not publicly disclosed how the attacker entered its network. Its online notice said the organization strengthened password requirements and implemented conditional access policies after the incident. Those changes show the controls the organization chose to improve, but they do not prove that weak passwords or missing policies caused the breach.
That distinction matters because nonprofits should learn from the incident without presenting assumptions as facts.
What Information Did the Nonprofit Breach Potentially Expose?
- Names
- Social Security numbers
- Dates of birth
- Medical or health information
- Treatment or diagnostic information
- Health insurance information
- Tax information
- Financial information
These records can create risks long after a password gets changed.
A criminal may combine someone’s medical information with a phone number, employer, birth date, or Social Security number. That combination can support highly convincing phishing messages. The person may receive a fake insurance notice, tax request, employment document, or healthcare message that appears credible because it contains accurate details.
The nature of the organization’s work makes that exposure particularly concerning. People seeking substance use treatment or employment assistance may face stigma if their information becomes public.
“It’s another sensitive population, like substance abuse treatment and employment services. There’s stigma-driven risk,” said Hilary Taylor, CEO, Onset Solutions.
Strong nonprofit cybersecurity protects people during moments when they may already feel vulnerable. It also protects the organization’s ability to maintain trusted relationships with clients, referral partners, government agencies, donors, and employees.
Why Are Nonprofits Attractive Cyberattack Targets?
Some nonprofit leaders still assume criminals focus only on large corporations. Attackers often look for a different combination: valuable data and fewer defenses. Nonprofits may offer both.
A small organization can hold years of donor, payroll, employee, client, and program information. At the same time, it may operate with a small IT budget, older equipment, limited monitoring, and employees who handle multiple roles.
“They have less protection than a lot of organizations, so they’re a higher target because it’s assumed that they aren’t going to have as much in place,” said Hilary.
Attackers can automate much of their work. They scan the internet for exposed remote-access services, unpatched devices, weak credentials, and vulnerable email accounts. They do not need to recognize the nonprofit’s name or understand its annual revenue before attempting entry.
Staff also communicate with donors, volunteers, vendors, government agencies, and community partners. That creates a steady flow of emails, links, invoices, shared documents, and account invitations. A carefully disguised phishing message can blend into normal work.
Our security breach case study describes how a 25-person organization learned that being small did not make it invisible to attackers. The attack led the organization to adopt stronger and more structured security practices.
Nonprofit Cybersecurity Controls That Could Reduce the Risk
Strong Passwords and Multi-Factor Authentication
Conditional Access Policies
Conditional access evaluates the circumstances surrounding a login. The organization can block or challenge access based on location, device condition, user role, or level of risk.
Hilary uses “impossible travel” as an example. If an employee signs in from Denver and then appears to sign in from another country shortly afterward, the system should recognize that the travel was impossible and block or challenge the second attempt.
“Ask your provider, ‘Do I have conditional access policies?’” Hilary recommended. “If the answer is no, they should add them, and you should understand what they’re preventing.”
Eligible nonprofits may receive substantial discounts on Microsoft cloud services.
Learn more about discounted software and how planned IT investments can support better protection in Enhancing Nonprofit Capabilities.
Email Security and Employee Training
Email security tools can analyze links, attachments, sender behavior, and signs of impersonation. Training gives employees the skills to recognize suspicious messages that technology does not stop.
Employees should know how to report a questionable email without forwarding it to coworkers. They should also know what to do if they clicked a link, entered a password, or approved an MFA request.
Fast reporting gives the IT team a chance to reset credentials, revoke active sessions, inspect the device, and review mailbox rules.
Patch Management and Vulnerability Scanning
Criminal groups regularly exploit known vulnerabilities in internet-facing devices, email systems, firewalls, and remote-access tools.
Automated patching helps close those openings. Vulnerability scanning verifies whether devices remain exposed because an update failed, a system reached the end of its supported life, or a configuration created a new weakness.
Effective nonprofit cybersecurity requires both. Installing patches without checking the results can leave leaders with a false sense of security.
Endpoint Detection and Response
Endpoint detection and response monitors computers for suspicious activity. It can flag malware, unauthorized tools, unusual file changes, and other behaviors that traditional antivirus may miss.
A layered approach connects endpoint protection with identity monitoring, email security, access controls, backups, and a security operations team.
Could Your Nonprofit Detect Unusual Data Access?
- A login from an unusual country
- Hundreds of files downloaded by one user
- An employee accessing folders outside that person’s role
- A new email-forwarding rule
- An unfamiliar application connecting to Microsoft 365
- A large transfer of information outside normal hours
- Security settings changed without authorization
- An account attempting to access several systems at once
Security information and event management can gather activity from cloud accounts, firewalls, servers, applications, and employee devices. Identity threat detection and response focuses on suspicious account behavior. Endpoint detection and response watches individual computers.
The value comes from connecting the alerts. One unusual login may have an innocent explanation. An unusual login followed by a new mailbox rule and a large file download requires immediate attention.
Learn more about these capabilities in our blog on Advanced Security Monitoring and Visibility. Continuous monitoring gives organizations a clearer record of what occurred and allows a security team to respond faster.
What Should a Nonprofit Do After Discovering a Breach?
The breached nonprofit’s public timeline shows the amount of work that begins after suspicious activity appears. The organization secured its environment, hired cybersecurity experts, investigated affected files, identified individuals, contacted government agencies, notified law enforcement, and established a call center.
Every nonprofit should prepare for those responsibilities before an incident occurs.
Make Nonprofit Cybersecurity Part of Mission Protection
A cybersecurity incident can interrupt services, create unplanned expenses, and weaken community confidence. For organizations that work with health information, financial records, or stigmatized populations, the consequences may reach directly into clients’ lives.
That makes nonprofit cybersecurity a leadership and governance responsibility. The board and executive team should understand what information the organization possesses, who can reach it, and how quickly the nonprofit could detect unusual activity.
Leaders should begin by asking their IT provider several direct questions:
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
- Does MFA protect every important account?
- Have we configured conditional access policies?
- Do we monitor unusual sign-ins and downloads?
- Are all devices receiving security updates?
- Do we scan for unpatched vulnerabilities?
- Can we isolate a compromised account or computer quickly?
- When did we last test our incident-response plan?
- How often do we review employee and vendor access?
- Do we retain sensitive information longer than necessary?
Answers such as “probably” or “we think so” deserve follow-up. Effective protection requires documented controls, regular testing, and clear accountability.
Onset Solutions has supported Denver-area organizations since 2001. We help nonprofits apply layered security, improve visibility, and build practical technology plans around real operational and budget needs.
Contact Onset Solutions to schedule a free IT assessment. The review can help your organization identify its most significant risks and create a practical plan to protect its data, people, and mission.