SURVIVORS
The stories of those under attack
-

Survivor - Humanitarian
“My colleagues got scared when confronted with this. The colleague who opened the email containing the malware started to feel guilty. We all did our best to reassure them. But there was this feeling of vulnerability, of being exposed.”
-

Survivor - Water & Sanitation
"I didn’t know what to do or who to turn to once we knew about the attack. How long had the breach been active? We had no idea of the extent of the hack.”
-

Survivor - Healthcare
“Nurses are running around. Doctors are running around. There’s no computers whatsoever they can use. This is a new reality we need to be better prepared for.”
-

Survivor - Mental Health
“It is difficult to understand why anyone would deliberately try to disrupt the work of an organisation that is relied on by people at their most vulnerable.”
ATTACK ON CLEAN WATER
A nonprofit organization focused on providing clean water across the APAC region suffered a significant cyberattack. The attack caused immediate disruptions to the organization’s operations, leading to delays in providing critical clean water services. Additionally, there are long-term concerns about the integrity of their data, potentially eroding donor trust and affecting future funding. This incident was a ransomware attack carried out by a cybercriminal group that operates a ransomware-as-a-service model. The attackers threatened to release sensitive information unless they were paid an extortion fee of $300,000.
Adapted from The Record, January 2024
-
Operational delay
Long-term data integrity issues
Impact to donor trust and funding
Loss of funds
-
SDG 6: Clean water and sanitation
SDG 16: Peace, Justice and strong institutions.
-
ATTACK ON COMMUNICATION
A nonprofit organization lost control of their Instagram account, a critical platform for their online presence. The loss of access to their Instagram account threatened to undermine the organization's credibility and disrupt their general activities. As their flagship online presence, the account's absence threatened to damage their reputation and hinder their ability to engage with supporters and the public. The incident began with a spear phishing attack via email, which appeared to come from Instagram. Two days after the attack, cybercriminals contacted the organization via WhatsApp, claiming responsibility and demanding a ransom to restore access. The attackers had altered the account’s email address, password, and phone number, ultimately disabling it.
Adapted from The Protect.ngo foundation, December 2021
-
ATTACK ON PRIVACY
A prominent nonprofit organization, known for its global operations and significant revenues, fell victim to a cyberattack carried out by a ransomware gang. The attack resulted in the theft of more than 6.8TB of sensitive data, including 800GB of financial records, email communications, HR files, and personal data, which included medical and health information. The exposure of this data possibly impacted the nonprofit’s operations, endangered their privacy, and damaged its reputation, potentially affecting its ability to function across its 116-country network. The ransomware gang known for targeting critical infrastructure and healthcare organizations, claimed responsibility for the attack. Although the charity wasn’t directly named, a post on the gang’s dark web data leak site described the victim as "the world’s leading nonprofit" with US$2.8 billion in revenues.
Adapted from The Record, September 2023
-
ATTACK ON SUSTAINABILITY
A nonprofit organization focused on exchanging reusable items to reduce landfill waste suffered a significant data breach. The breach affected 7 million of the nonprofit's members, with sensitive information being sold on the dark web. The breach also reportedly included the data of the organization's executive director. The stolen data was available on the dark web for months, before discovered. The specific method used by the malicious actor to infiltrate the organization’s network remains unknown. Members have been cautioned not to interact with suspicious emails by clicking on links or downloading files.
Adapted from SecurityWeek, September 2023
ATTACK ON FOOD SUPPLY
A hunger relief organization based in the United States fell victim to a cyberattack that resulted in a significant financial loss. The organization was scammed out of more than $923,000, a substantial amount that could severely affect its ability to provide essential services. Beyond the financial hit, this incident threatened to undermine trust in the organization's operations, potentially impacting future support and donations. The attackers carried out a phishing campaign by intercepting legitimate emails from a construction company and sending a fraudulent invoice in its place. The organization unknowingly paid the fake invoice, falling prey to the scam.
Adapted from PhillyVoice, December 2020
-
Loss of funds
Loss of trust in organization
Impacting the delivery of essential services
Violation to the right of privacy
-
SDG 2: Zero hunger