It’s easy to hear about attacks on large companies and government victims in your day-to-day and not see your own nonprofit or association in them, or whether your cybersecurity would hold up. However, that shouldn’t be the case. Today we’re looking at how challenging cyber incidents can be for even the most prepared Minnesota entities, how AI is changing the world of social engineering, how managed IT services can help you stay secure, and a plan you can put in place to better protect yourself from ransomware.
Key Takeaways
- A city with a dedicated IT team needed the National Guard after a ransomware attack, so a small nonprofit can’t count on size or luck when it comes to security.
- Verizon’s 2025 report found ransomware in 88% of breaches at smaller organizations.
- AI has changed the approach to social engineering attacks forever.
Table of Contents
One Year, Three Minnesota Cyberattacks
The Ransomware That Struck St. Paul
In July 2025, the group behind the ransomware attack – Interlock – stole city data, then locked down systems and threatened to publish what it took (this is known as the double extortion model).
Fortunately, St. Paul had an incident response plan for just such an occasion, according to Jaime Wascalus, St. Paul Director of the Office of Technology and Communications. However, it wasn’t enough.
St. Paul decided to engage a contracted cybersecurity firm, and when that wasn’t enough, Gov. Tim Walz issued an emergency executive order. On July 29, Walz activated the Minnesota National Guard’s cyber unit after stating that the attack exceeded the city’s capacity to respond.
A Cyberattack That Impacted Over 30 Minnesota Water Systems
In late July 2026, Minnesota IT Services said more than 30 municipal water systems were targeted in a coordinated cyberattack.
In Braham, the attack shut down the controls for the city’s well and treatment plant, and staff had the system running again within about an hour and a half. Plymouth, Maple Plain, and South St. Paul all reported problems with automated controls for their water systems.
Plymouth’s public works director, Michael Thompson, said the city plans for events like this.
“We just had to physically go out to lift stations or the water towers, just to ensure they were functioning and running properly,” said Thompson.
Winona County Paid a Ransom, Then Was Attacked Again
Winona County was hit twice in 2026. A ransomware attack detected on January 22 forced county networks offline. The county negotiated and paid a ransom of $128,539.57 with help from its insurance carrier.
About $50,000 was covered by insurance, and about $78,000 came from county levy money.
“Although making the payment in connection with the January incident was a difficult choice, we determined it was the necessary approach to best serve the interests of Winona County residents and employees,” the Winona County Board of Commissioners said.
Less than three months later, on April 7, a second ransomware strain hit the network. Officials said it was completely separate from the first one in January.
However, the severity of the incident prompted Gov. Walz to authorize the National Guard and the Bureau of Criminal Apprehension (BCA) to step in and assist with emergency operations and network hardening.
The Financial Squeeze on Minnesota Nonprofits
Minnesota nonprofits are running lean – while the pressure to serve their communities rises and giving/funding declines.
In the Minnesota Council of Nonprofits’ pulse check, survey respondents reported the following since January 1, 2025:
- 83% saw higher expenses
- 68% saw higher demand for services
- 59% saw less money from foundations or corporate giving
- 54% saw less government funding
National figures point the same direction. The Urban Institute found that one-third of nonprofits reported a government funding disruption in early 2025.
Meanwhile, the Center for Effective Philanthropy reported that almost 60% of nonprofit CEOs said foundation grants were harder to secure. Despite these numbers, technology spending is rising – which is good because the threat is too.
In BDO’s 2025 survey of public charity leaders, 64% planned to increase their technology spend. However, you have to be careful when investing in cybersecurity. Buying tools does not protect your organization by itself. You need a strong strategy and careful monitoring.
Verizon’s 2025 Data Breach Investigations Report found ransomware in 88% of breaches at organizations with fewer than 1,000 employees, compared with 39% at larger ones.
Cybercriminals love to go after an easy target but, to make matters worse, they now have a tool to make it even easier to fool your staff.
AI Tools Have Made Attacks More Personalized
The FBI’s San Francisco office warned in May 2024 that criminals use AI to write targeted phishing messages with proper grammar and spelling, and to clone the voice or video of co-workers and business partners.
Their December 2024 alert on generative AI fraud adds that criminals use AI-generated images of disasters to solicit donations for fraudulent charities.
The FBI’s 2025 Internet Crime Report was the first to include an AI section. It included 22,364 complaints and nearly $893 million in losses due to AI-related scams – which only covers reported losses.
So, the old advice of “Look for typos in your email” no longer works. An email, video, or phone call that seems to come from your President asking for a change in a payment can:
- Read perfectly
- Look like them
- Sound like them
This also means that a criminal can create a fake social profile that can be made to look like your organization’s, so they can solicit fraudulent donations.
They can gain access to your donors’ information through an unpatched vulnerability. They can also use social engineering to gain access to your organization’s network and use your email to do the same.
There are many approaches bad actors can take, but they all boil down to one thing. They can very quickly destroy the trust you’ve built with your donors and your community when you don’t have the proper cybersecurity measures in place.
The Cybersecurity Measures You Can Put in Place this Month
Nightly backups played a big part in St. Paul’s decision not to pay a ransom. The steps below may give you that same option. Each one is small enough for one person to start working on this month.
1. Turn on multi-factor authentication (MFA) for email and admin accounts.
The FBI recommends multi-factor authentication to strengthen account security.
2. Regularly back up your data.
Test your restores to ensure they will work when you need them. Pick one file server or mailbox and restore it this month.
3. Review who has access to what data - including volunteers and contractors.
Make sure you remove accounts for people who left the organization. Keep a list of which volunteers/contractors use personal devices for work.
4. Train your staff, volunteers, and contractors to spot phishing, then test them.
Give everyone with a login short cybersecurity awareness training every month, then send simulated phishing emails on a schedule. Include AI-written messages in the examples, since typos no longer give an attacker away. Treat a click on a testing email as a teaching moment. Start this month by booking one 30-minute session and sending one test email.
5. Write an incident response plan with a callback rule.
Write a one-page incident response plan that names who decides what happens next, who calls your IT support, and who talks to donors. Then add one rule that states, “Any request to change payment details must get confirmed by calling a specific number,” which you will annotate.
If you need the first hours after a cyberattack mapped out, Teal’s guide covers the response steps in this article.
How an MSP Can Help a Nonprofit Lower its Risk
A managed IT services provider with nonprofit experience lowers ransomware risk by providing the team and tools your team could not otherwise afford, such as:
- Cybersecurity analysts
- Cybersecurity consulting
- Incident response support
- Endpoint Detection & Response (EDR)
- Managed Detection & Response (MDR)
- 24/7 Security Operations Center (SOC)
- Security awareness training
- Account access reviews
- Patching
- Vulnerability scanning
- Tested, offline backups
- Offboarding management
- MFA management
The stories in this article show why the monitoring piece is vital. The IT team noticed the suspicious activity using endpoint detection and response software the state had deployed with federal grant funds.
A nonprofit often operates with just one IT person – which leaves no one watching for activity like that overnight. An MSP, on the other hand, will supply it.
In practice, that looks like this:
- Monitoring around the clock: Unusual logins and unfamiliar server traffic get flagged before files can get encrypted.
- Security controls that stay current: Multi-factor authentication, patching, endpoint protection, and backup tests are on a schedule instead of on someone’s to-do list.
- Training for staff, contractors, and volunteers: People learn about the latest tactics, what AI-powered phishing looks like, and routinely tested to see if they retained the information or not.
- People to call: After the attack, St. Paul’s technology director said the experience reinforced the value of relationships that existed beforehand. A provider can be an invaluable resource to rely on when you really need it.
- Predictable IT budget: Monthly costs are much easier to plan around than an emergency bill.
Managed IT providers can also provide you with a collection of people who understand your budget situation, volunteer-heavy staff, and the importance of protecting donor data.
Why Careful Management and Process Discipline Are Important
A legal association switched to Teal because their leaders were unhappy with their previous provider’s customer service and cybersecurity basics. We quickly learned why.
During the first day of onboarding, they were hit with a business email compromise. You see, the account of a former employee had never been disabled – which is why offboarding processes and access reviews are so important. So, the attackers used it to get into the association’s CRM and send phishing emails to its members.
Our help desk flagged the activity immediately and escalated it to our cybersecurity team. We were quickly on a call with the association’s executive director and our cyber VP to contain it. An IT provider that has handled cases like this knows the places to look for first, and who to call when one is already open.
Ask any provider you consider:
- Whether it works with nonprofits and associations today
- Who responds after hours
- Whether it will test a restore with you before an incident
If you already have an IT person/team but need cybersecurity help, ask about tailored support for them. The provider can cover monitoring and response, and your person keeps the work they know best. Teal has provided nonprofit IT support since 2000.
Where to Go Next
You need to make some decisions made before you’re faced with a cyber incident: who restores the backups, who makes the decisions, who calls whom. You also should make sure you have at least the five items in the section, The Cybersecurity Measures You Can Put in Place this Month.
If you’re interested in managed IT services, we’ve provided nonprofit IT support since 2000. We’d be happy to speak with you to see if we’re the right fit for your needs.
If you already have an IT person/team but need cybersecurity help, we can help with that too. Ask about our tailored managed cybersecurity services.








