The short version
- Money moves on one message. Decide that no single message, call, or sign-in can move money: a callback on a number already on file, a hold on the first payment to a changed account, and a second approver at the bank.
- One sign-in can reach everything, and records you keep are records you report. Decide that the people who move money or run systems use phishing-resistant sign-in, and that the organization keeps less.
- Your name can be used without touching your systems. Decide who owns the domain, the giving page, the payment-app accounts, and the social handles before the next disaster.
After the floods
After the July 4, 2025 floods in the Texas Hill Country, scammers set up Venmo accounts impersonating the newly created donation account of a Hill Country volunteer fire department, American Banker reported. Venmo, which gave no official reason, temporarily froze the department’s real account until July 7; the department’s president believed the surge of donations to a brand-new account triggered the freeze. For the days that mattered most, the real channel was closed and the copycats were open. No one inside the department had to be deceived for the loss to happen. The copycats needed only its name.
Texas nonprofits hold three things worth stealing: money in motion, records about the people they serve, and a name that donors trust. This article follows each through the public record, using Texas cases from 2018 to 2026, then sets out what a proportionate defense looks like, what it costs, and who should own it. One pattern runs through all of it: a control set up in advance can break the chain, whether or not anyone was deceived.
The money
Thieves got into the bank accounts of a Texas faith-based social services nonprofit and moved between $500,000 and $1 million to international accounts. The organization recovered most of it through its bank and insurance. Its filing also reports new controls: staff training, stronger sign-in, and security monitoring.
The loss is public because the organization reported it. A nonprofit that files Form 990 must report a significant diversion of its assets, including theft by any person. A full-text search of Texas e-filed returns found seven Texas 501(c)(3)s that disclosed phishing, social engineering, cyberattack, or wire fraud losses from 2021 through 2024. The search was not exhaustive. Each organization deserves credit for disclosing, so none is named here.
From the filings
Seven Texas nonprofits disclosed cyber losses on their Form 990 returns, 2021 through 2024.
| Organization | Reported loss | How it happened, as disclosed | What followed |
|---|---|---|---|
| Faith-based social services nonprofit | $500,000 to $1 million | Bank accounts accessed; funds sent to international accounts | Most recovered; training and new controls added |
| Youth organization | $500,000 to $1 million | Fake sign-in page; unauthorized transfers | Most recovered; ongoing training |
| Senior living community | $500,000 to $1 million | Wire fraud; incident not described | Not described |
| Private school | $500,000 to $1 million | Vendor impersonation | No recovery disclosed; internal controls added |
| Church-affiliated ministry | $250,000 to $500,000 | Phishing; a contractor payment redirected | About a quarter recovered by the end of 2024 |
| Nonprofit service provider | $250,000 to $500,000 | Payment to a false contractor | Recovered through insurance; vendor verification added |
| Volunteer-run arts group | Under $1,000 | Phishing | Not described |
Four of the seven involved a fake sign-in page or a misdirected vendor or contractor payment. Some attackers skip the staff entirely: the Fifth Circuit found that a ring member emailed a small Fort Worth charity’s bank pretending to be the charity and obtained cashier’s checks drawn on its account. The same move works on funders, grantees, and members, and each is a party a nonprofit can brief in advance.
What stops the payment
- A callback on a number already on file for every bank change that arrives by email, phone, or letter, as the FBI and the FTC both advise.
- A hold on the first payment to a changed account, and a second approver at the bank for outgoing wires and new payees, so one stolen sign-in cannot move money alone. Outside bookkeepers belong under the same rules.
- Rules agreed with the bank in advance and published to funders, grantees, and donors, with positive pay wherever checks are issued and a recall plan written down.
- Insurance confirmed in writing, since most insurers cannot cover voluntarily transferred funds. Ask the broker what pays for social engineering and funds transfer fraud.
Stewardship includes the systems
Nonprofit leaders already practice stewardship. Boards approve budgets, auditors test financial controls, and donors trust that a gift reaches the mission it was meant for. The systems that move that money and hold client records are part of the same duty. A wire sent to a false contractor is a stewardship loss whether it began with a forged invoice or a stolen password.
The organization is responsible for making sure one mistake does not become a loss on its own. Employees do their part by following procedure and reporting what looks wrong.
My position is that the controls that matter most are rarely the most expensive. They are written down, owned by a named person, and tested before they are needed.
The records
When attackers want records instead of money, the cost arrives as downtime, notice letters, and lawsuits.
By Ascension’s account, its 2024 attack began on one laptop. A September 2025 letter from Senator Ron Wyden to the FTC sets out what Ascension told his staff: in February a contractor clicked a malicious search result on an Ascension laptop, and the attackers later used Kerberoasting, a way of cracking service account passwords, to take over privileged accounts before pushing ransomware. When it hit on May 8, it disrupted Ascension’s hospitals around Austin and in Waco. The Texas hospitals got their electronic health records back on June 4, almost a month later, and staff described interim systems as taking three to five times longer.
Most incidents are quieter. In September 2026 the Attorney General’s breach listing included churches, ministries, a community center, an adoption agency, a legal-aid foundation, a workforce board, and private universities. Letters often come months after the intrusion, and lawsuits follow: a Houston university’s proposed settlement, entered while it denied wrongdoing, would let class members claim up to $4,500 in extraordinary losses. This article makes no finding about whether any notice was timely.
When the data sits on someone else’s platform
One vendor can stall many organizations at once. The Change Healthcare breach affected more than 11 million Texans, and one Houston-based community health network processed about half of its claims through Change; its chief executive at the time said it had to extend a bank line of credit.
In 2020, ransomware hit Blackbaud, whose customers, the Texas Attorney General said, included educational institutions, healthcare groups, cultural organizations, and nonprofits holding Texans’ data. The FTC alleges that the attacker “purportedly” started with one customer’s login and password, and that Blackbaud paid 24 Bitcoin for a promise to delete the stolen data. Blackbaud’s first notices said donor bank and Social Security numbers were not accessed; the SEC found that by the end of July 2020 its staff knew the attacker had reached that data for some customers. Blackbaud neither admitted nor denied the FTC’s allegations.
What each nonprofit had stored set its exposure. A Texas university told donors that its development office does not store card, bank, or Social Security data. A Houston hospital told patients, as KPRC 2 reported, that free-text fields in its fundraising database may have held patient names, dates of birth, and limited clinical information. Free-text fields are where sensitive data collects without anyone deciding to store it.
What limits the damage
- Identity hardening against the Ascension path: phishing-resistant sign-in for the people who run systems, separate admin accounts, and long or managed service account passwords.
- Backups that restore on a known clock, one copy offline and restore times tested, with downtime procedures that are drilled, not only written.
- Less data kept. Keep Social Security, bank, and clinical details out of donor systems, free-text fields, and shared drives, and purge on a board-approved schedule, which three FTC commissioners called a critical part of data security.
- Vendor contracts with the terms Texas and the FTC now require of Blackbaud: breach roles and notice duties and a set time limit for keeping backups, plus certified deletion at exit.
- Breach counsel and a forensic firm chosen before they are needed, so the review of whose records were in the files ends sooner.
The name
The fire department’s experience holds one detail worth planning for. Venmo offers a separate charity profile for 501(c)(3)s, and American Banker reported that the department’s newly created account was a business profile, which could not be converted without deleting it. The account type is a choice best made before a disaster. On July 17 the Texas Attorney General announced an investigation into the schemes that diverted donations meant for the department. No outcome had been announced by this article’s evidence cutoff.
The same floods produced a fake fundraiser posing as the family of a person who died in the floods. Its creator took a plea deal and, according to court records KPRC reported, was sentenced to three years in prison in July 2026. News 4 San Antonio found dozens of Facebook pages mixing AI-generated images with real flood scenes to drive donations to fraudulent links. The Attorney General has issued charity-scam warnings after Hurricane Harvey, the Uvalde shooting, and the floods of 2025 and 2026.
Impersonation costs the real nonprofit three ways. A gift sent to a copycat is revenue the organization never receives. The donation channel itself can go dark, as the fire department’s did. Donors told by the Attorney General to be wary of text solicitations bring that caution to the real appeal. Most Texas charities do not have to register with the state, so there is no general registry of charities to check. The organization’s own page is the reference point.
A public voice on human rights or religious freedom draws a different attacker. A federal indictment unsealed in March 2025 (S.D.N.Y. 24 Cr. 687) alleges that an officer of China’s Ministry of Public Security directed a contractor to compromise the email accounts of a Texas-based organization focused on promoting human rights and religious freedom in China, in 2018 and again in 2020. These are unproven allegations. A May 2024 CISA-led guide treats advocacy, faith-based, cultural, academic, and diaspora organizations that defend human rights and democracy as high-risk.
What protects the name
- An official giving page published before the disaster, listing every authorized donation method, payment handle, and approved third-party fundraiser, linked from the organization’s social profiles.
- Payment-app accounts opened in calm conditions, under the account type meant for charities, with the organization’s name and close variants claimed on the major platforms.
- A reporting path and a freeze plan agreed in advance: the platform, the Attorney General’s Consumer Protection Division at 1-800-621-0508, the National Center for Disaster Fraud at 866-720-5721, and a bank contact who can review a hold, with two published channels so one hold does not take giving offline.
- One owner for the whole set: the email domain and its anti-spoofing settings, the giving page, payment-app accounts, social handles, and the bank’s rules for requests made in the organization’s name.
What to do about it
What is not enough on its own
- Annual awareness training. Fake sign-in pages and calls showing a church’s own bank on caller ID are built to deceive a careful person, and training does not add a second approver.
- MFA that can be phished. The FBI has warned about device-code phishing and OAuth consent phishing, which get around it.
The legal floor
This is general information from statute, regulation, and contract text, not legal advice. A person doing business in Texas that owns or licenses computerized data containing sensitive personal information must notify the individuals whose data was, or is reasonably believed to have been, acquired by an unauthorized person. That notice is due without unreasonable delay and no later than 60 days after the organization determines that a breach occurred. The Attorney General must also be notified within 30 days when 250 or more Texans are involved (Bus. and Com. Code 521.053). The Texas Data Privacy and Security Act exempts nonprofits. A 2025 safe harbor, chapter 542, bars exemplary damages against a business entity under 250 employees that can show it implemented and maintained a qualifying program at the time of the breach. The program must conform to a listed framework such as NIST CSF 2.0 or the CIS Controls at every size, and whether the chapter reaches nonprofits at all is a question for counsel. Money brings duties too. Federal awards carry cybersecurity safeguards down to subrecipients. The Texas HHS Data Use Agreement, a contract term HHS writes into its agreements, requires contractors to report a breach within 1 hour for data from a federal system of records, which includes Medicaid data, and within 24 hours for other confidential information.
What to put in place at your size
| Under 20 employees | 20 to 99 employees | 100 to 249 employees | |
|---|---|---|---|
| Framework | NIST CSF 2.0, starting from NIST’s Small Business Quick-Start Guide | CIS Controls IG1, which chapter 542 names for this band | NIST CSF 2.0, with CISA’s performance goals as the goal set |
| Microsoft 365 | Business Basic with security defaults, unless the risk triggers below apply | Business Premium | Business Premium |
| People | A named internal owner (described below) and a monitoring provider | An IT generalist or managed service provider, plus monitoring | An in-house security lead becomes realistic |
Business Basic with security defaults is a defensible start for a small organization with no managed laptops and no high-risk work. Move to Premium once the organization manages laptops, moves large payments, holds health or client records, sends staff to policy events, or fits CISA’s high-risk profile, because Conditional Access is what lets it require phishing-resistant sign-in for the people who matter most. Headcount does not set the risk.
At every size, the baseline is the same:
- Phishing-resistant MFA as the goal, which CISA calls the gold standard, starting with administrators, payment approvers, and executives.
- A named account for every employee and volunteer (Texas DIR), with admin accounts kept out of daily work.
- The payment rules and backups set out above, and a written, exercised incident plan with the Texas deadlines, kept in hard copy.
The technical baseline behind these, from legacy authentication and email authentication to network segmentation and the hosted donation page, is the IT lead’s list and sits in the full report’s control checklist.
What it costs
The public evidence does not support one correct number for security spending. The Center for Internet Security’s The Cost of Cyber Defense offers a planning rule of 1 percent of revenue, from an IT budget at 5 percent of revenue and a cybersecurity budget at 20 percent of that, and it concludes that implementing CIS Controls IG1 should cost less. Both percentages are modeling assumptions, not measured nonprofit spending, and CIS’s cost estimates leave out labor, training, and consulting. For a $5 million organization, the rule gives a $50,000 cybersecurity budget. Use it as a check, not a target.
Licensing is the small line. Microsoft ended its donated Business Premium grant at renewals from July 1, 2025, and Premium now costs nonprofits $5.50 per user per month: $1,650 a year for 25 staff, against $6,600 at the commercial price. The larger lines are labor and monitoring. CIS puts managed services for organizations of 10 to 100 employees from $44,000 a year.
FEMA’s Nonprofit Security Grant Program funds physical and cybersecurity enhancements at nonprofits at high risk of terrorist or extremist attack, up to $200,000 per site, through the Office of the Governor’s eGrants portal, whose notice opens early in the year. Insurers ask about controls too, and Travelers’ MFA supplement asks whether MFA is required for all employees using web-based or cloud email. Bring evidence to renewal: MFA on email, endpoint protection, and a dated restore test.
Who does the work
Deciding who owns security comes before deciding whom to hire. CISA’s guidance for small businesses calls leaving security to the IT team alone a common mistake and tells the chief executive to select a Security Program Manager, who need not be a security expert or even an IT professional, and who reports at least monthly. The role can sit with an operations or finance lead.
Hiring a specialist is expensive. The Texas median wage for an information security analyst was about $130,000 in May 2025, and with benefits at the BLS rate for private industry in the region that includes Texas (all occupations, not an IT or nonprofit rate), the loaded cost comes to roughly $182,000 by this article’s arithmetic, more than three times the cybersecurity budget the CIS rule gives a $5 million organization. Most Texas nonprofits will combine a named internal owner with a managed service provider, a monitoring service, or a fractional security leader. A good provider contract requires MFA on every provider account, as a joint CISA advisory advises, writes down which controls the provider owns and which stay inside, and requires incident notice that leaves room inside the Texas deadlines.
Buy outcomes, not headcount
For most Texas nonprofits, a security hire is the wrong first step: one person is a single point of failure. What an organization needs is outcomes it can verify. Every account that can move money or reach client records signs in with phishing-resistant MFA. Every bank change is confirmed by a callback, and the callback is logged. A restore from the offline copy has been timed. Access for a departing employee or a former vendor is removed the same day. The contract is where those outcomes get written down.
Managed service providers are partners in this work, and the strongest partnerships are the ones where both sides can point to the same list of who owns which control. What stays inside is ownership, meaning a named person who receives the reports and makes the call, and the board’s judgment about risk.
The first 90 days
- First 30 days: close the cheapest paths. Name the Security Program Manager, adopt the callback rule, issue security keys or passkeys to administrators and payment approvers, make one offline backup copy and test a restore, and report systems without MFA to the board.
- By 60 days: set the program’s shape. Choose the licensing line and budget it, separate admin accounts and remove unused ones, review vendor contracts for MFA, breach notice, and data destruction, and print a one-page incident plan with the Texas deadlines.
- By 90 days: test and document. Run two tabletops, a bank-change request from a compromised vendor mailbox and a restore from the offline copy, adopt a retention schedule, review cyber and crime coverage with the broker, and map the program to NIST CSF 2.0 or CIS IG1 with a dated record.
What the board should ask
The 2026 NACD and Internet Security Alliance handbook on cyber-risk oversight states that its principles apply to nonprofit boards. This article offers six questions, and none requires technical training:
- Who in management is accountable for cyber risk, and how do we hold them to it?
- What stops a fraudulent payment or a changed bank account?
- Who signs in with phishing-resistant MFA today, and who does not?
- When did we last restore from an offline copy, and how long did it take?
- Can we meet the Texas deadlines: individuals within 60 days, the Attorney General within 30 days for 250 or more Texans?
- Who owns our name: the domain, the giving page, the payment accounts, and the social handles?
A one-page quarterly report can answer all six: who is on phishing-resistant sign-in, the payment changes verified by callback, the date and length of the last restore, the time it took to remove a departing user’s access, the vendor contracts still missing notice or deletion terms, and the risks accepted, each with an owner and a review date.
About this article
This article draws only on public sources: organizations’ own statements and filings, state and federal records, court documents, and named reporting, each checked against its source. Ransomware group statements are reported as claims, and allegations as allegations. The seven organizations known only from their own filings were found through full-text search of Texas e-filed Form 990 returns; they are described by broad type, with amounts banded. Other organizations are described rather than named unless the name adds substance, and their public sources are linked. The recommendations are defensive design judgments, not findings that any organization named or described here lacked a control. The evidence cutoff is September 23, 2026.
Full report. The complete study behind this article: the money, the records, and the name, with the Texas legal and board reference, a control checklist, a 30/60/90-day plan, Texas resources, and the timeline.