Case study · September 23, 2026 · 19 min read

The Cyber Risks Facing Texas Nonprofits, and How to Get Ahead of Them

What Texas nonprofits lose to fraud and breaches, and the controls that break the chain.

The short version

  • Money moves on one message. Require a callback on a number already on file, a hold on the first payment to a changed account, and a second approver at the bank.
  • One sign-in can reach everything, and records you keep are records you report. Phishing-resistant sign-in for the people who move money or run systems, and less data kept.
  • Your name can be used without touching your systems. One named person owns the domain, the giving page, the payment-app accounts, and the social handles before the next disaster.

After the floods

After the July 4, 2025 floods in the Texas Hill Country, scammers set up Venmo accounts impersonating the newly created donation account of a Hill Country volunteer fire department, American Banker reported. Venmo, which gave no official reason, temporarily froze the department’s real account until July 7; the department’s president believed the surge of donations to a brand-new account triggered the freeze. For the days that mattered most, the real channel was closed and the copycats were open. No one inside the department had to be deceived for the loss to happen. The copycats needed only its name.

Texas nonprofits hold three things worth stealing: money in motion, records about the people they serve, and a name that donors trust. This article follows each through the public record, using Texas cases from 2018 to 2026, then sets out what a proportionate defense looks like, what it costs, and who should own it. One pattern runs through all of it: a control set up in advance can break the chain, whether or not anyone was deceived.

The money

Thieves got into the bank accounts of a Texas faith-based social services nonprofit and moved between $500,000 and $1 million to international accounts. The organization recovered most of it through its bank and insurance. Its filing also reports new controls: staff training, stronger sign-in, and security monitoring.

The loss is public because the organization reported it. A nonprofit that files Form 990 must report a significant diversion of its assets, including theft by any person. A full-text search of Texas e-filed returns found seven Texas 501(c)(3)s that disclosed phishing, social engineering, cyberattack, or wire fraud losses from 2021 through 2024. The search was not exhaustive. Each organization deserves credit for disclosing, so none is named here.

Organization Reported loss How it happened, as disclosed What followed
Faith-based social services nonprofit $500,000 to $1 million Bank accounts accessed; funds sent to international accounts Most recovered; training and new controls added
Youth organization $500,000 to $1 million Fake sign-in page; unauthorized transfers Most recovered; ongoing training
Senior living community $500,000 to $1 million Wire fraud; incident not described Not described
Private school $500,000 to $1 million Vendor impersonation No recovery disclosed; internal controls added
Church-affiliated ministry $250,000 to $500,000 Phishing; a contractor payment redirected About a quarter recovered by the end of 2024
Nonprofit service provider $250,000 to $500,000 Payment to a false contractor Recovered through insurance; vendor verification added
Volunteer-run arts group Under $1,000 Phishing Not described

Four of the seven involved a fake sign-in page or a misdirected vendor or contractor payment. Community IT Innovators, a managed IT provider for nonprofits, found that all three 2024 wire fraud incidents among its clients also involved a compromised internal account: in that sample, the mailbox takeover and the payment fraud were one incident seen from two desks. Some attackers skip the staff entirely.

Your bank, your funders, your members

A small Fort Worth charity is the only Texas nonprofit named as a business email compromise victim in the federal releases reviewed for this article. The Fifth Circuit found that a ring member emailed the charity’s bank pretending to be the charity and obtained cashier’s checks drawn on its account. The request went to the bank, not to the charity’s staff.

The same move works on funders. Attackers controlling a California nonprofit finance director’s email told a California county that the nonprofit’s bank account had changed. Elsewhere, impostors posing as a nonprofit persuaded a Kentucky city official to wire $3.9 million owed to the nonprofit to a shell company; the bank and the city recovered all of it. Criminal complaints also allege that a look-alike domain asked a foundation’s grantee to email its bank details instead of uploading them to the grant portal.

Texas churches see it by phone. In September 2026 the Texas Annual Conference of the United Methodist Church published guidance telling its churches to confirm any vendor banking change by calling a known contact at a trusted number, after scams that included calls whose caller ID showed the church’s own bank; it said some churches had lost money.

The lure is not new. In April 2020 an Episcopal diocese in North Texas warned its members that scam emails were posing as its bishop and clergy. Its answer was a control: everyone doing diocesan business uses a diocese-managed email account, so staff can act fast if one is compromised.

Each of these is a party a nonprofit can brief in advance: its bank, its funders, its grantees, and its members. Greater Houston Community Foundation does this for donors, telling them it will never update or request changes to wiring instructions by email.

Paper still counts. Houston Landing reported that a Houston foundation found fraudulent checks drawn on its account late in 2022 and adopted positive pay with its bank in early 2023.

What stops the payment

  • A callback on a number already on file, for every bank change that arrives by email, phone, or letter, as the FBI and the FTC both advise.
  • A hold on the first payment to a changed account, released only after the callback is logged and a second person has reviewed it.
  • A second approver at the bank for outgoing wires and new payees, so one stolen sign-in cannot move money alone. Outside bookkeepers belong under the same rules.
  • Positive pay wherever checks are issued, as the FBI and the Postal Inspection Service advise.
  • Rules agreed in advance with the bank for requests made in the organization’s name, and published to funders, grantees, and donors.
  • A recall plan. IC3 says time is of the essence: call the bank, request a recall, and file at www.ic3.gov, typed directly.
  • Insurance confirmed in writing. Two of the Texas organizations above recovered money through insurance, but most insurers cannot cover voluntarily transferred funds. Ask the broker what pays for social engineering and funds transfer fraud.

Stewardship includes the systems

Nonprofit leaders already practice stewardship. Boards approve budgets, auditors test financial controls, and donors trust that a gift reaches the mission it was meant for. The systems that move that money and hold client records are part of the same duty. A wire sent to a false contractor is a stewardship loss whether it began with a forged invoice or a stolen password.

The organization is responsible for making sure one mistake does not become a loss on its own. Employees do their part by following procedure and reporting what looks wrong.

My position is that the controls that matter most are rarely the most expensive. They are written down, owned by a named person, and tested before they are needed.

The records

When attackers want records instead of money, the cost arrives as downtime, notice letters, and lawsuits.

By Ascension’s account, its 2024 attack began on one laptop. A September 2025 letter from Senator Ron Wyden to the FTC sets out what Ascension told his staff: in February a contractor clicked a malicious Bing search result on an Ascension laptop, and the attackers later took over privileged accounts, using a technique called Kerberoasting, before pushing ransomware. When it hit on May 8, it disrupted Ascension’s hospitals around Austin and in Waco. The Austin American-Statesman reported that some Ascension Texas emergency rooms set up a process to divert ambulances; Ascension Texas called diversions a normal course of operation and said its local hospitals were not diverting as of May 14. The Texas hospitals got their electronic health records back on June 4, almost a month later, and staff described interim systems as taking three to five times longer.

Other Texas nonprofit systems have lost weeks too. After a 2022 ransomware attack on a national nonprofit health system, six of its Houston-area hospitals went on internal disaster status, and physicians ordered on paper for about two weeks.

Charities feel it too. On November 10, 2024, a North Texas nonprofit with a chain of retail stores closed all of them, Comparitech reported, citing a company-wide technical issue that later reporting showed was a cyber incident. A ransomware group later claimed responsibility, and in the reporting found the organization has not attributed the attack. By late February 2025 it had begun notifying 6,274 Texans.

Most incidents are quieter. In September 2026 the Attorney General’s breach listing included an Austin church, two ministries, a Houston Jewish community center, an adoption agency, a legal-aid foundation, a workforce board, a tennis association, and five private universities. Letters often come months after the intrusion, and at some organizations most of that time goes to file review: working out whose records were in the files. One San Antonio university’s notice went out about seven months after its August 2022 intrusion, and a ransomware group had posted a claim in the meantime. At a legal-aid foundation, file review ended about eight months after the intrusion. Counts can also grow long after the first notice: one Texas nonprofit health system’s first public figure in 2022 was 15,062 affected individuals, and the federal breach portal now lists 842,874 for the same incident. Texas deadlines run from the date an organization determines that a breach occurred, and this article makes no finding about whether any notice was timely.

Lawsuits follow. Plaintiffs’ lawyers said in a court filing that 41,825 class members were eligible under a Texas university’s preliminarily approved settlement. A Houston university’s proposed settlement, entered while it denied wrongdoing and set for a final approval hearing on October 5, 2026, would let class members claim up to $4,500 in extraordinary losses.

When the data sits on someone else’s platform

One vendor can stall many organizations at once. The Change Healthcare breach affected 11,331,028 Texans, and one Houston-based community health network with clinics across Texas processed about half of its claims through Change; its chief executive at the time said it had to extend a bank line of credit.

In 2020, ransomware hit Blackbaud, whose customers, the Texas Attorney General said, included educational institutions, healthcare groups, cultural organizations, and nonprofits holding Texans’ data. The FTC alleges that the attacker “purportedly” started with one customer’s login and password, moved across Blackbaud-hosted environments, and took customer data, and that Blackbaud paid 24 Bitcoin for a promise to delete it. Blackbaud’s first notices said donor bank and Social Security numbers were not accessed; the SEC found that by the end of July 2020 its staff knew the attacker had reached that data, in unencrypted form, for some customers. Texas’s share of the later multistate settlement was $2,766,155, and Blackbaud neither admitted nor denied the FTC’s allegations.

What each nonprofit had stored set its exposure. A Texas university told donors that its development office does not store card, bank, or Social Security data, and a Dallas community foundation said the same of its Blackbaud data, the Dallas Morning News reported. A Houston hospital told patients, as KPRC 2 reported, that free-text fields in its fundraising database may have held patient names, dates of birth, treating physicians, and limited clinical information. Free-text fields are where sensitive data collects without anyone deciding to store it.

Encryption and certification are not the same as control. A UK donor database provider, one of its customers said, confirmed that encrypted data was downloadable in readable form because the attacker used valid credentials, most likely a compromised AWS access key. The Baptist Paper reported that the provider advertised ISO 27001:2022 certification when the breach occurred. A certification is a starting point, not proof.

What limits the damage

  • Downtime procedures that are drilled, not only written, for clinical care, revenue, and client services.
  • Segmentation and alerts on bulk outbound transfers, since attackers can spend weeks inside a network first; at one health system it was about two weeks.
  • Identity hardening against the Ascension path: long or managed service account passwords, retiring weak Kerberos encryption, and separate admin accounts.
  • Backups that restore on a known clock, with one copy offline and restore times tested.
  • MFA on every external door, starting with mail, and alerts on new forwarding rules.
  • Monitoring for the organization’s name on leak sites, since claims can surface before notices go out.
  • Less data kept. Keep Social Security, bank, and clinical details out of donor systems, free-text fields, and shared drives, and purge on a board-approved schedule. Three FTC commissioners called a retention and deletion schedule a critical part of data security.
  • Vendor contracts that match what Blackbaud is now bound by: breach roles and notice duties, a backup retention schedule, and encryption of sensitive fields. Also ask for written updates when a vendor’s findings change, since early statements can be wrong, and certified deletion when the relationship ends.
  • A current data map, with breach counsel and a forensic firm chosen before they are needed, so file review ends sooner.
  • A second claims connection and a cash reserve sized to a disrupted billing cycle, so one vendor outage is survivable.

The name

The fire department’s experience holds one detail worth planning for. Venmo offers a separate charity profile for 501(c)(3)s, and American Banker reported that the department’s newly created account was a business profile, which could not be converted without deleting it. The account type is a choice best made before a disaster. FBI San Antonio warned on July 9 that fraudsters were likely to pose as charities, and on July 17 the Texas Attorney General announced an investigation into the schemes that diverted donations meant for the department. No outcome had been announced by this article’s evidence cutoff.

The same floods produced a fake fundraiser in a grieving family’s name. A Florida woman set up crowdfunding campaigns posing as the family of a person who died in the floods. She was charged under Texas’s online impersonation statute and, according to court records KPRC reported, accepted a plea deal and was sentenced to 3 years in prison in July 2026. News 4 San Antonio found dozens of Facebook pages mixing AI-generated images with real flood scenes to drive donations to fraudulent links. The Attorney General issued charity-scam warnings after Hurricane Harvey, the Uvalde shooting, and the floods of 2025 and 2026.

Impersonation costs the real nonprofit three ways. A gift sent to a copycat is revenue the organization never receives; FBI El Paso warns that fake charities divert donations to their creators. The donation channel itself can go dark, as the fire department’s did. Donors told by the Attorney General to be wary of text solicitations bring that caution to the real appeal. Most Texas charities do not have to register with the state, so there is no state registry of charities to check. The IRS Tax Exempt Organization Search confirms that an organization exists and is exempt, but it does not say which payment handle is real. The organization’s own page is the reference point.

A public voice on human rights or religious freedom draws a different attacker. A federal indictment unsealed in March 2025 (S.D.N.Y. 24 Cr. 687) describes a victim it calls Organization-2: a Texas-based organization focused on promoting human rights and religious freedom in China. The indictment alleges that an officer of China’s Ministry of Public Security directed the contractor i-Soon to compromise its email accounts in or around July 2018, and to compromise the organization again in or around June 2020. These are unproven allegations. Such targeting is not unusual: Microsoft’s 2025 Digital Defense Report puts think tanks and NGOs at 7 percent of the nation-state notifications it sent customers, and a May 2024 CISA-led guide treats advocacy, faith-based, cultural, academic, and diaspora organizations that defend human rights and democracy as high-risk.

What protects the name

  • An official giving page published before the disaster, listing every authorized donation method, payment handle, and approved third-party fundraiser, linked from the organization’s social profiles.
  • Payment-app accounts opened in calm conditions, under the account type meant for charities, with the organization’s name and close variants claimed on the major platforms and early listing on verified hubs such as GoFundMe’s flood relief page.
  • A rapid reporting path to the platform, the Attorney General’s Consumer Protection Division at 1-800-621-0508 or its online complaint form, and the National Center for Disaster Fraud at 866-720-5721.
  • A freeze planned with the bank, with expected volume and a contact who can review a hold agreed in advance, and two published channels so one hold does not take giving offline.
  • The device code sign-in path closed wherever possible, as Microsoft recommends, and phishing-resistant keys for the people who travel and speak for the organization.
  • Invitations verified the way finance verifies bank changes, since an FBI-led advisory lists impersonated journalist interviews and conference invitations as lure themes.
  • One owner for the whole set: the email domain with DMARC set to reject, the giving page, payment-app accounts, social handles, and the bank’s rules for requests made in the organization’s name.

What to do about it

What is not enough on its own

  • Annual awareness training. Fake sign-in pages and calls showing a church’s own bank on caller ID are built to deceive a careful person, and training does not add a second approver.
  • MFA that can be phished. The FBI has warned about device-code phishing and OAuth consent phishing, which get around it.

This is general information from statute, regulation, and contract text, not legal advice. A person doing business in Texas that owns or licenses computerized data containing sensitive personal information must notify the individuals whose data was, or is reasonably believed to have been, acquired by an unauthorized person. That notice is due without unreasonable delay and no later than 60 days after the organization determines that a breach occurred. The Attorney General must also be notified within 30 days when 250 or more Texans are involved (Bus. and Com. Code 521.053). The Texas Data Privacy and Security Act exempts nonprofits. A 2025 safe harbor, chapter 542, bars exemplary damages against a business entity under 250 employees that can show it implemented and maintained a qualifying program at the time of the breach. The program must conform to a listed framework such as NIST CSF 2.0 or the CIS Controls at every size, and whether the chapter reaches nonprofits at all is a question for counsel. Money brings duties too. Federal awards carry cybersecurity safeguards down to subrecipients. The Texas HHS Data Use Agreement, a contract term HHS writes into its agreements, requires contractors to report a breach within 1 hour for data from a federal system of records, which includes Medicaid data, and within 24 hours for other confidential information.

What to put in place at your size

Under 20 employees 20 to 99 employees 100 to 249 employees
Framework NIST CSF 2.0, with NIST’s Small Business Quick-Start Guide as the starting point CIS Controls IG1, which chapter 542 names for this band NIST CSF 2.0, with CISA’s performance goals as the goal set
Microsoft 365 Business Basic with security defaults, unless the risk triggers below apply Business Premium Business Premium
People A named internal owner (CISA’s Security Program Manager, described below) and a monitoring provider An IT generalist or managed service provider, plus monitoring An in-house security lead becomes realistic

Business Basic with security defaults is a defensible start for a small organization with no managed laptops and no high-risk work. Move to Premium once the organization manages laptops, moves large payments, holds health or client records, sends staff to policy events, or fits CISA’s high-risk profile, because Conditional Access is what lets it require phishing-resistant sign-in for the people who matter most. Headcount does not set the risk.

At every size, the baseline is the same:

  • Phishing-resistant MFA as the goal. CISA calls it the gold standard and names FIDO/WebAuthn as the only widely available form (CISA). Start with administrators, payment approvers, and executives.
  • Legacy authentication blocked (SCuBA MS.AAD.1.1v1), and SPF, DKIM, and DMARC moving to reject, with automatic external forwarding off, as CISA’s Exchange Online baseline sets out.
  • Payment changes verified out of band, as set out above.
  • Backups that survive the attack, automatic and encrypted, with the offline copy and timed restores set out above (CISA Cyber Essentials).
  • Card donations through a processor-hosted page or redirect, validated as the card acquirer requires (PCI SSC).
  • A named account for every employee and volunteer (Texas DIR), with admin accounts kept out of daily work.
  • A written, exercised incident plan with the Texas deadlines, kept in hard copy.

What it costs

The public evidence does not support one correct number for security spending. The Center for Internet Security’s The Cost of Cyber Defense offers a planning rule: an IT budget at 5 percent of revenue and a cybersecurity budget at 20 percent of that, or 1 percent of revenue in all, and it concludes that implementing CIS Controls IG1 should cost less. Both percentages are modeling assumptions, not measured nonprofit spending, and CIS’s cost estimates leave out labor, training, and consulting. For a $5 million organization, the rule gives a $50,000 cybersecurity budget. Use it as a check, not a target.

Licensing is the small line. Microsoft ended its donated Business Premium grant at renewals from July 1, 2025, and Premium now costs nonprofits $5.50 per user per month. For 25 staff that is $1,650 a year, against $6,600 at the commercial price. The larger lines are labor and monitoring: CIS puts managed services for organizations of 10 to 100 employees from $44,000 a year.

FEMA’s Nonprofit Security Grant Program funds physical and cybersecurity enhancements at nonprofits at high risk of terrorist or extremist attack, and a nonprofit may request up to $200,000 per site. Texas nonprofits apply through the Office of the Governor’s eGrants portal, where the FY 2026 notice opened January 12 and closed March 12, 2026, months before FEMA’s own deadline, so watch for the FY 2027 notice early in the year. Insurers also ask about controls: Travelers’ MFA supplement asks whether MFA is required for all employees using web-based or cloud email. Bring evidence to renewal: MFA on email, endpoint protection, and a dated restore test.

Who does the work

Deciding who owns security comes before deciding whom to hire. CISA’s guidance for small businesses calls leaving security to the IT team alone a common mistake and tells the chief executive to select a Security Program Manager, who need not be a security expert or even an IT professional, and who reports at least monthly. The role can sit with an operations or finance lead.

Hiring a specialist is expensive. The Texas median wage for an information security analyst was $129,890 in May 2025. BLS puts benefits at 28.7 percent of total compensation for private industry in the West South Central division, which includes Texas (all occupations, not an IT or nonprofit rate), which brings the loaded cost to roughly $182,000 by this article’s arithmetic, more than three times the cybersecurity budget the CIS rule gives a $5 million organization. Most Texas nonprofits will combine a named internal owner with a managed service provider, a monitoring service, or a fractional security leader. A good provider contract requires MFA on every provider account, as a joint CISA advisory advises; writes down which controls the provider owns and which stay inside; sets who may disable an account or isolate a device; and requires incident notice that leaves room inside the Texas deadlines.

Buy outcomes, not headcount

For most Texas nonprofits, a security hire is the wrong first step: one person is a single point of failure. What an organization needs is outcomes it can verify. Every account that can move money or reach client records signs in with phishing-resistant MFA. Every bank change is confirmed by a callback, and the callback is logged. A restore from the offline copy has been timed. Access for a departing employee or a former vendor is removed the same day. The contract is where those outcomes get written down.

Managed service providers are partners in this work, and the strongest partnerships are the ones where both sides can point to the same list of who owns which control. What stays inside is ownership, meaning a named person who receives the reports and makes the call, and the board’s judgment about risk.

What the board should ask

The 2026 NACD and Internet Security Alliance handbook on cyber-risk oversight states that its principles apply to nonprofit boards. This article offers six questions, and none requires technical training:

  1. Who in management is accountable for cyber risk, and how do we hold them to it?
  2. What stops a fraudulent payment or a changed bank account?
  3. Who signs in with phishing-resistant MFA today, and who does not?
  4. When did we last restore from an offline copy, and how long did it take?
  5. Can we meet the Texas deadlines: individuals within 60 days, the Attorney General within 30 days for 250 or more Texans?
  6. Who owns our name: the domain, the giving page, the payment accounts, and the social handles?

A one-page quarterly report can answer all six.

About this article

This article draws only on public sources: organizations’ own statements and filings, state and federal records, court documents, and named reporting, each checked against its source. Ransomware group statements are reported as claims, and allegations as allegations. The seven organizations known only from their own filings were found through full-text search of Texas e-filed Form 990 returns; they are described by broad type, with amounts banded. Other organizations are described rather than named unless the name adds substance, and their public sources are linked. The recommendations are defensive design judgments, not findings that any organization named or described here lacked a control. The evidence cutoff is September 23, 2026.

Let's talk about your technology.

A free 30-minute intro call. No pitch, no obligation, a straight answer either way.