Skip to content
Statistics

Cybercrime Against Nonprofits (2026): Latest Statistics & Protective Strategies

VolunteerBadge Team·October 7, 2026·8 min read

30% rise in cyberattacks, 60% of nonprofits hit in 2 years, $2M+ breach costs. Data-driven guide for nonprofit leaders.

Screen for $5

FCRA-compliant volunteer background checks. No monthly fees.

Nonprofit organizations now face an unprecedented cybersecurity crisis. Nonprofits experienced a 30% year-over-year increase in the number of weekly cyberattacks in 2024 , and nonprofits were the second-most targeted sector last year . This report aggregates the latest 2024–2026 threat data, financial impact metrics, and vulnerability analysis to help nonprofit and faith-based leaders understand the true scope of the threat—and what protective measures matter most. For a deeper dive into sector trends, see our full cybercrime and compliance statistics hub.

Methodology & Honesty Note: This report draws from primary sources including the FBI's Internet Crime Complaint Center (IC3), Verizon's Data Breach Investigations Report (2025–2026), Identity Theft Resource Center (ITRC), Sophos ransomware surveys, academic research (NPCIR), and sector-specific surveys (NetHope, Nonprofit Technology Network, BDO). All figures are sourced and hyperlinked; we omit unverified estimates. Nonprofit-specific data is highlighted where available; sector-wide data is noted. This is a living document, refreshed annually.

Key takeaways

30% YoY surge in weekly cyberattacks on nonprofits (2024)
60% of nonprofits experienced cyberattack in past 2 years
2M average data breach cost for nonprofits (USD)
59% of nonprofits lack full-time IT staff

The Scale of the Threat: Attack Volume & Targeting

Nonprofits experience an average of 1,636 cyber attacks per week —a relentless barrage of probing, phishing, and payload deployment attempts. Yet this raw number understates impact: 60% of nonprofits have reported experiencing a cyberattack in the last two years , meaning the threat is not abstract. Nonprofits were the second-most targeted sector, and Cloudflare's Project Galileo reports a 241% increase of cyber-attacks between 2024 and 2025 .

Nonprofits (2nd most targeted) High
Nation-state targeting by sector 4th
DDoS attacks on civil society orgs 2nd most impacted

Ransomware: The Dominant Attack Vector

Ransomware has emerged as the most destructive threat to nonprofits. Verizon's 2026 Data Breach Investigations Report found ransomware involved in 48% of breaches , up from 44% in 2025 . For smaller organizations—a typical nonprofit profile—the risk is even steeper: Ransomware appeared in 88% of breaches at organizations with fewer than 1,000 employees, compared with 39% at larger ones .

The financial toll is staggering. Initial ransom demands climbed 47% year over year to an average above $1 million in 2026, though 64% of victim organizations did not pay the ransom . However, recovery costs—downtime, data restoration, legal, notification—often exceed the ransom itself. The average total cost of a ransomware attack—including downtime, recovery, and reputational damage—ranges between $1.8 million and $5 million per incident in 2025 .

Ransomware as share of all confirmed data breaches (Verizon DBIR 2024–2026)

70% of the ransomware claims processed in 2026 involved both encryption and data exfiltration together, a combination known as double extortion . This tactic—stealing data before locking systems—creates leverage: nonprofits face threats not only to operations but to donor, volunteer, and beneficiary privacy.

Data Breaches & Stolen Data

The broader data breach landscape remains severe. 3,322 American data breaches were reported in 2025, an increase of 4% from 2024 . Nonprofits are disproportionately represented in breach reports.

Religious/Nonprofit organizations accounted for 4% of 2025 security breaches (91 incidents) according to state-level data. While that percentage seems modest, nonprofits are targeted because they hold especially sensitive data: donor records (names, emails, giving history, payment methods), volunteer personal information, client/beneficiary records (in health and social-service nonprofits), and financial systems.

68%
70%

The financial breach cost is severe. The average cost of a data breach reaches up to $2 million for nonprofits, a sum many smaller organizations cannot absorb without mission disruption or major donor impact. This aligns with detailed nonprofit data breach statistics published in our cybersecurity hub.

The Human Element: Phishing & AI-Powered Social Engineering

In 2024, 68% of breaches involved a human element, such as phishing or human error . Nonprofits are especially vulnerable: 59% of nonprofits have no full-time IT staff at all, relying instead on volunteers, part-time contractors, or staff members who handle technology alongside their primary responsibilities . Staff wearing multiple hats are prime targets for convincing phishing emails.

The threat has intensified with AI-powered social engineering. Phishing attacks rose over 1,200% last year . 87% of organizations experienced AI-driven cyberattacks last year . The FBI's 2025 Internet Crime Report included 22,364 complaints and nearly $893 million in losses due to AI-related scams .

Vulnerability% of NonprofitsImpact
No full-time IT staff59%Limited security monitoring, patch management, incident response
No documented incident response plan68%Chaotic, costly recovery; delayed law enforcement notification
Lack formal cybersecurity policy70%No staff training; inconsistent password/access practices
No clear website security plan32%Unpatched donation systems; donor data exposure risk
Unprepared for cybersecurity challenges35%No leadership buy-in; reactive vs. proactive posture
Nonprofit Cybersecurity Preparedness Gaps (multiple 2024–2025 surveys)

FBI Cybercrime Losses: The Broader Economic Impact

The FBI's Internet Crime Complaint Center (IC3) documents the staggering financial toll. In 2025, IC3 logged 1,008,597 complaints and $20.877 billion in losses, with reporting averaging close to 3,000 complaints per day . This represents a 26% increase in losses from 2024 .

Investment-related fraud was the largest component of these losses, followed by business email compromises and tech support scams . For nonprofits, business email compromise (BEC) is particularly dangerous: BEC resulted in close to $2.8 billion in losses in 2024 alone. Scammers impersonate executives or vendors, tricking finance staff into wire transfers or vendor payments—attacks that nonprofits with thin accounting teams are especially prone to.

FBI IC3 Total Cybercrime Losses: 2024 vs. 2025 (FBI IC3 2025 Annual Report)

Why Nonprofits Are Prime Targets

Cybercriminals systematically target nonprofits for a simple reason: high-value data, weak defenses, limited incident response budgets, and organizational reluctance to involve law enforcement (which can complicate donor communications).

  • Sensitive Data: Nonprofits are often targeted because they have limited security infrastructures and because the data they store—like financial data and donor records—is so valuable .
  • Resource Constraints: Nonprofit organizations, which typically have lower budgets and fewer cybersecurity defenses, are particularly at risk. Smaller entities may be seen as prime targets due to their increased dependence on third-party service providers and remote or hybrid work environments .
  • Geopolitical Targeting: Cybercriminals are becoming more sophisticated with the assistance of artificial intelligence. Ransomware-as-a-service enables these criminal entities to acquire credentials, custom-developed ransomware, and ransom payment processing services with minimal technical expertise. As a result, nonprofit organizations are increasingly vulnerable to sophisticated cyber threats stemming from geopolitical tensions .
  • Funding Crisis Leverage: One-third of nonprofits reported a government funding disruption in early 2025 , making recovery from breach costs nearly impossible without emergency fundraising.

Threat Landscape & Emerging Patterns

The cybersecurity threat ecosystem is evolving. 138 groups were active in 2025, up 41% from 2024 . Ransomware-as-a-service (RaaS) platforms now lower the technical bar for entry, enabling less sophisticated criminal actors to launch professional attacks. The attack category of ransomware dropped from 27.5% (2024) to 18.6% (2025), while DDoS attack types increased from 5.8% in 2024 to 9.3% in 2025 , showing a tactical shift in the threat landscape; attackers are diversifying beyond ransomware alone.

DDoS attacks are surging. Cloudflare's Project Galileo reports a 241% increase of cyber-attacks between 2024 and 2025, with human rights and civil society organizations the second most impacted by DDoS attacks . Nonprofits advocating for controversial causes or operating in hostile regions face particular risk.

Beyond operational and financial damage, breaches create legal liability. 70% of nonprofits reported an increase in their cyber risk profile in 2025 . Donors and beneficiaries are increasingly litigious over data loss. State attorneys general are scrutinizing nonprofit data practices, especially in healthcare and social services.

Additionally, a breach can expose donor records, client data, or financial systems, erode public trust, interrupt program delivery, and trigger regulatory scrutiny or litigation . Nonprofits that accept federal funding also face new compliance mandates: Organizations that are recipients or subrecipients of U.S. government funds are now subject to stricter cybersecurity requirements, similar to OFAC and FCRA compliance frameworks. Learn more about compliant volunteer and employee vetting and related FCRA background check requirements.

What this means for your volunteer program

Cybercrime against nonprofits creates a direct risk to your volunteer program and mission. Here's why:

  • Volunteer Data Risk: Your volunteer management system likely contains names, emails, phone numbers, addresses, Social Security numbers (for tax forms or background checks), and emergency contacts. A breach or ransomware attack exposes all of it—creating legal liability and public trust damage.
  • Donor Intelligence Leakage: Ransomware double-extortion often includes publication of donor databases, embarrassing your major supporters and deterring future giving.
  • Mission Interruption: Downtime from ransomware can halt volunteer scheduling, online registration, background check processing, and communication during critical event periods. For food banks, shelters, and disaster response nonprofits, this means lives affected.
  • Screening Compliance Risk: Many nonprofits now conduct identity-verified background checks on high-risk volunteers. If your screening vendor or internal systems are breached, you face liability for failing to protect volunteer and subject data—and regulatory queries about your vetting process.

VolunteerBadge was built specifically for nonprofits operating under resource constraints. Our FCRA-compliant background checks ($5 per person, no monthly fees, character references included) provide the identity verification and criminal record screening nonprofits need—without forcing you to build in-house infrastructure or manage vendor compliance burden. We integrate with your existing volunteer systems and deliver results in days, not weeks. Learn more about our nonprofit pricing, and read how proper volunteer screening protects your organization from liability and reputational harm.

Beyond screening, nonprofits should adopt the fundamentals: multi-factor authentication (MFA) on all staff and volunteer accounts, regular staff cybersecurity training (especially on phishing), encrypted volunteer databases, and incident response planning. If you've experienced a breach or ransomware incident, our compliance academy offers guidance on notification, law enforcement reporting, and recovery.

Ready to strengthen your volunteer screening?
VolunteerBadge offers FCRA-compliant background checks with identity verification, no monthly subscription fees, and integration with your existing volunteer systems. Start your free trial today.

Download the data

⬇ Download the data (.xlsx)

Frequently asked questions

Q: What's the average cost of a nonprofit data breach?
A: The average cost of a data breach reaches up to $2 million , including forensics, legal fees, notification costs, credit monitoring, lost revenue, and reputational damage. Smaller nonprofits often cannot absorb this without emergency fundraising.

Q: Which attack type is most common against nonprofits?
A: Breach attack types remained consistently above 60% in the years 2023, 2024, and 2025 , with ransomware as the second-largest vector. In 2024, 68% of breaches involved a human element, such as phishing or human error , making staff training essential.

Q: Should we pay a ransom if attacked?
A: No. 64% of victim organizations did not pay the ransom , and for good reason: 80% of organizations that pay are attacked again within 12 months, and only 4% recover all their data . Consult law enforcement (FBI) and your cyber insurance provider instead.

Q: How can we reduce phishing risk among staff and volunteers?
A: Educating staff on best practices for cybersecurity to prevent phishing attacks and other threats is critical. Implement multi-factor authentication (MFA), mock phishing drills, and clear reporting procedures. Most importantly, foster a non-punitive culture where staff feel safe reporting suspicious emails.

Q: What should we do if we suspect a breach?
A: Document everything. Isolate affected systems (shut down the affected server or network segment without turning it off, so forensics can capture evidence). Contact law enforcement (FBI field office or local cybercrime unit), your cyber insurance provider, legal counsel, and a forensic incident response firm. Delay public notification until you understand scope and legal obligations. Consult state attorney general data breach notification laws.

Q: Does cyber insurance cover ransomware?
A: Most policies do, but terms vary widely. More nonprofits are investing in cyber insurance to mitigate the financial impact of data breaches and cyberattacks. Cyber insurance can cover costs related to data recovery, legal fees, and notification expenses. It provides a safety net, allowing nonprofits to recover more quickly from cyber incidents . Review your policy before an incident and ensure your board understands coverage limits and exclusions.

Sources & references

  1. BDO: The Crucial Role of Cybersecurity for Nonprofit Organizations in 2025
  2. NetHope: 2025 State of Humanitarian and Development Cybersecurity Report
  3. MGO CPA: Cybersecurity for Nonprofits 2025
  4. MDPI: Trends in Non-Profit Cybersecurity (NPCIR) 2023–2025
  5. DesignData Corp: Strengthening Nonprofit Cybersecurity in 2025
  6. Tardigrade Technology: Key Nonprofit Cybersecurity Statistics 2025
  7. TealTech: What Recent Cyberattacks Can Teach Minnesota Nonprofits
  8. Tech Insider: Ransomware Data Theft Up 275% (2026)
  9. The Modern Nonprofit: Nonprofits Are Prime Targets for Cyberattacks
  10. SOCRadar: Top 20 Ransomware Statistics 2025
  11. StationX: Ransomware Statistics 2026
  12. Bright Defense: 500+ Ransomware Statistics 2026
  13. Viking Cloud: 46 Ransomware Statistics 2026
  14. ITDaily: Zscaler Ransomware Report 2026
  15. Identity Theft Resource Center: 2025 Annual Data Breach Report
  16. North Carolina Department of Justice: 2025 Data Breach Report
  17. BankInfoSecurity: Data Breaches in America Hit All-Time Record 2025
  18. Anvilogic: IC3 Reports $16.6B in Cybercrime Losses 2024
  19. ASIS International: FBI IC3 Report: Half of 2025 Fraud Losses Linked to Cryptocurrency
  20. Outseer: FBI 2024 Fraud Statistics
  21. FBI Internet Crime Complaint Center: 2
VolunteerBadge

Ready to stop overpaying for background checks?

Full national criminal checks at $5. Free address history. FCRA compliant from day one. No monthly fees, no contracts.

Create Free Account

Legal Disclaimer: The content on this page is for informational purposes only and does not constitute legal advice. VolunteerBadge and ScreenForge Labs, LLC are not law firms and do not provide legal counsel. FCRA requirements and applicable laws vary by jurisdiction and circumstances. For guidance specific to your organization, please consult a qualified attorney.

AI Content Transparency: We use AI tools to assist in the research and drafting of our blog content. That said, the opinions, perspectives, and editorial judgment in every article reflect the author's genuine views and real-world experience. We believe in full transparency about how content is created — because trust matters as much in publishing as it does in background screening.