Desk live·
ForensicPost
Breaches/Nonprofit/File 25-0614b

78% of Nonprofits Say Their Cyber Resilience Is Insufficient

Humanitarian and nonprofit organisations reported sharply rising attacks through 2025, with 78% saying their cyber resilience is insufficient. Their data subjects are the most vulnerable in this corpus.

Constructed geometry · not a chart of case data
TargetNonprofit sector
ActorMultiple
S. Rosler12 min readConfidence: medium2 sources reviewed

Research on the nonprofit and humanitarian sector reports a substantial rise in attack volume through 2024 and 2025, with one monitoring programme citing a 241% increase between the two years, and 78% of surveyed organisations saying their cyber resilience is insufficient for their needs.

The Beneficiary Data Is The Most Sensitive In This Database

A humanitarian organisation holds records on refugees, asylum seekers, survivors of violence, people in conflict zones, and individuals whose safety may depend on their location or affiliation not being known.

This corpus has filed sensitive categories throughout — medical records at 25-1010, children at 25-0927, social services case files at 25-0819. Beneficiary data in a humanitarian context can carry consequences those do not: exposure may place a person at physical risk from a state or an armed group.

And There Is No Notification Anyone Could Usefully Send

The corpus filed at 25-0408 that a research association’s correspondents included people in countries where contact with a foreign body carries consequences, and that a consumer-oriented notification regime has nothing to say about them.

The humanitarian case is that at scale. A person displaced by conflict has no stable address, may not have the phone number on file, and telling them may itself be dangerous.

The Funding Structure Is The Worst In The Corpus

This desk has filed the funding gap for water districts at 26-0729, county governments at 25-0918 and small law firms at 25-0910. Nonprofits sit below all of them.

Donor-funded organisations are judged on the proportion of income reaching programmes. Security spending is overhead, and overhead is the metric supporters are taught to minimise. The incentive structure actively penalises the investment.

Graded medium: the figures come from sector self-assessment and a single monitoring programme, and this desk has no named incident to anchor them.

This is an analysis file

Built on published sector research, listed below. Figures are self-reported or drawn from one monitoring programme. No named incident is recorded here. Corrections: corrections@forensicpost.com.

Sources
  1. 2025 state of humanitarian and development cybersecurity reportNetHope
  2. The crucial role of cybersecurity for nonprofit organizations in 2025BDO
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary