Criterica Intelligence — production models trained on real court records, not synthetic data
Data Breach — MDL No. 2972

Blackbaud, Inc.

U.S. District Court for the District of South Carolina

The Blackbaud, Inc., Customer Data Security Breach litigation was centralized before Judge Joseph F. Anderson, Jr. in the District of South Carolina in December 2020, consolidating claims arising from a ransomware attack and data breach at Blackbaud, a software vendor serving nonprofits, educational institutions, and healthcare organizations with donor-management and customer relationship management tools. Like other vendor-breach MDLs, this docket's claim population spans individuals connected to the breach only through their relationship with one of Blackbaud's many institutional clients rather than a direct relationship with Blackbaud itself.

With 26 pending actions six years after centralization, this docket reflects the layered structure typical of vendor-breach litigation: resolution risk depends not only on Blackbaud's own data-security practices and the adequacy of its breach notification, but potentially on the data-security obligations of the specific downstream institution whose donor, alumni, or patient data was exposed for a given claimant. That layered structure can extend the range of legal questions at issue relative to a single-company breach, even as the docket's core standing and certification questions have had years to develop.

Blackbaud's role as a widely used vendor across the nonprofit and education sectors makes this docket a useful example of how a single vendor's security failure can generate litigation spanning an unusually broad range of downstream institution types — from universities to hospitals to charitable organizations — each with its own data-sensitivity profile. Criterica Intelligence's platform tracks this multi-sector vendor-breach pattern across every active MDL, since the diversity of downstream institutions affected is itself a structural factor shaping how a docket like this develops and resolves. A companion capital brief on this docket is available through Criterica Capital.

Frequently Asked Questions
What happened in the Blackbaud breach?

A ransomware attack and data breach at Blackbaud, a vendor providing donor-management and CRM software broadly across the nonprofit, education, and healthcare sectors, exposed personal information belonging to the customers, donors, and patients of its many client organizations.

Why does this docket involve such a broad range of affected individuals?

Because Blackbaud served an unusually wide range of institutional client types, the breach exposed data belonging to individuals connected to universities, hospitals, and nonprofit organizations alike, each with its own data-sensitivity profile.

How does the downstream-institution structure affect resolution risk?

It can extend the range of legal questions at issue, since a given claim may implicate both Blackbaud's own security practices and the data-security obligations of the specific downstream institution involved.

What does this docket illustrate about vendor-breach litigation generally?

It shows how a single software vendor's security failure can generate litigation spanning an unusually diverse set of downstream sectors, a structural pattern Criterica Intelligence tracks distinctly from breaches confined to a single industry.

Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.

← All Pending MDLsFunding brief on Criterica Capital →