NPO Authentication Attacks Skyrocketing

(image from pexels.com)

Data is high stakes for nonprofit around the globe, managing donor records, refugee data, and sensitive government grants. This growing digital footprint, and a lack of funding for cybersecurity, has made organizations increasingly vulnerable to security threats. 

According to the authors of a new report from technology firm Okta titled Nonprofits at Work 2026, there is a difficult reality: While artificial intelligence (AI) offers ways for nonprofits to serve their communities as budgets shrink, it puts this already heavily targeted and under-funded sector in an even more precarious position. The data suggests that for many mission-driven organizations, the path to a high-tech future is currently blocked by a significant security gap.

There has been a surge in malicious activity. Two years ago, the ratio of threats to authentications in the nonprofit sector was just 2.6%. It increased to 18% last year. That figure has skyrocketed to 78% this year, according to data from Okta.

Nearly four out of five login attempts at nonprofits are now fraudulent, making it the most-attacked industry in the Okta dataset and surpassing historically “hard” targets such as finance and energy. This rise in threat activity suggests that attackers see the nonprofit sector as a target-rich and less defended environment.

Used as a “financial force multiplier,” AI could help nonprofits handle growing workloads with shrinking resources. Data in the report found that 80% of larger nonprofits (more than 200 employees) are already deploying or piloting autonomous AI agents. However, adoption is outstripping oversight. Three out of four (76%) nonprofits lack a formal AI strategy, and 58% have no restrictions in place for the use of AI tools. According to the authors, this creates a “shadow AI” nightmare. Staff are using free tools like ChatGPT to automate individual workflows, but these apps often sit outside the protection of Single Sign-On (SSO) and Multi-Factor Authentication (MFA), leaving sensitive data exposed.

Nonprofits ranked last among all 16 industries studied for automated lifecycle management (LCM) — the process of automatically onboarding, offboarding, and managing user access.

To safely navigate the agentic age, nonprofit leaders should move beyond manual security, according to the authors. Scaling impact requires strong identity security — continuous authentication, automated lifecycle management, and robust governance for both human and machine identities.

Read the full report at https://www.okta.com/resources/whitepapers/nonprofits-at-work-2026/