CSIDB logo
Incident

National Trust

Incident posture

Attack window
May 2020
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
National Trust
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeting third-party cloud provider Blackbaud compromised volunteer data belonging to a UK heritage conservation organization. Exposed information included names, dates of birth, addresses, contact details, and equality monitoring records, though financial data remained unaffected. The provider notified the organization weeks after the incident, asserting stolen data had been destroyed. The organization reported the breach to national data protection authorities, confirmed its membership systems were unaffected, and established a dedicated communication channel for impacted volunteers while reviewing data management security practices with the vendor.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In May 2020, US cloud computing and software provider Blackbaud suffered a ransomware attack that compromised data belonging to the National Trust’s volunteer program. The UK-based heritage conservation charity was notified by Blackbaud on July 16, 2020, about the incident, which exposed personal information of past and present volunteers and volunteer program applicants. Compromised data included names, dates of birth, gender, addresses, and contact details, along with limited equality monitoring information classified as sensitive. National Trust Chief Information Officer Jon Townsend confirmed in an August 7, 2020 email to volunteers that no financial data or membership systems were affected by the breach. Blackbaud assured the Trust that all stolen data related to their systems had been destroyed following the attack. The ransomware incident specifically targeted Blackbaud’s infrastructure rather than National Trust’s direct systems.

Upon receiving notification from Blackbaud in July, the National Trust initiated response procedures including formal reporting to the UK Information Commissioner’s Office. The organization directly notified affected volunteers via email on August 7, 2020, detailing the scope of compromised information while emphasizing that no volunteer action was required. Townsend’s communication acknowledged the concern caused by the breach and reiterated the Trust’s commitment to data protection, stating they were reassessing data management security protocols. The charity established a dedicated email contact point for volunteer inquiries related to the incident. National Trust collaborated with Blackbaud to investigate the attack’s specifics while maintaining that their membership databases remained unaffected throughout the event. This breach exclusively impacted volunteer program data managed through Blackbaud’s third-party systems.

Sources

Sources available to members: 1 source.

CSIDB