The #FTC went after #Blackbaud for its poort security, #databreach in 2020, and incident response. A ton of provisions in the proposed order, but no monetary penalty.
Direct link to proposed order: https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-order-will-require-blackbaud-delete-unnecessary-data-boost-safeguards-settle-charges-its-lax
I like how they included that after paying $250k to the threat actors to get them to delete the data, "The company never verified, however, that the hacker actually deleted the stolen data, according to the complaint."