Security/ business-email-compromise · nonprofit-security · email-scams · small-business

Small Nonprofit's Email Breach Left It Offline for Three Days

A small Alabama nonprofit went offline for three days after a compromised email account was used to blast fake money pleas to its partners worldwide.

A small Alabama nonprofit spent three days offline this spring after its email account was hijacked to blast a money scam at its partners.

Vivian's Door trains and supports underserved and minority-owned businesses, work that puts it in contact with some of those companies' financial data. In March, founder Janice Malone started fielding calls from contacts around the world who said they'd gotten emails "begging for money" that she never sent. Her third-party IT team pulled the organization's systems offline for three days while it investigated and closed the hole. It's not clear from what's been reported how the attacker got in, or whether any of that financial data was actually taken.

This is the unglamorous reality of most breaches: a small nonprofit, a skeleton IT setup, and one compromised inbox turning into a worldwide scam blast and a three-day operational blackout. Organizations like Vivian's Door rarely have budget for dedicated security staff, which makes a single hijacked account enough to do real damage to trust and partnerships built over years.

Coverage of this incident leaned hard on the idea that AI is supercharging attacks like this one. Nothing in what's been reported ties artificial intelligence to Vivian's Door's compromise; it reads like a classic business email scam, the kind that's been hitting under-resourced organizations long before anyone added AI to the pitch.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →