Okta's 2026 sector report flags 78% of nonprofit login attempts as threats, the highest share of any industry it tracks. Most of the fixes are free.

Your login page is now the most contested piece of real estate your nonprofit owns. In Okta's Nonprofits at Work 2026 report, 78% of authentication attempts across the company's nonprofit customers were flagged as threats. That makes nonprofits the most-attacked industry in Okta's dataset, ahead of historically hard targets like finance and energy.
The trend line is the part worth forwarding. Okta says the same ratio was 2.6% two years ago and 18% last year. This year, nearly four out of five login attempts at nonprofit organizations in the dataset are fraudulent. The NonProfit Times covered the report this week, noting that the sector's growing digital footprint and thin cybersecurity funding have left it increasingly exposed. Read the numbers together and the pivot is hard to miss: attackers have rebalanced toward the sector least staffed to absorb them.
One caveat before you panic, and one reason not to relax. The caveat: this is Okta's customer telemetry, not a census of every nonprofit, and a flagged attempt is an attempt, not a breach. The reason not to relax: whoever, or whatever, is knocking, the door they try first is a reused password. A staffer's password exposed in some unrelated consumer breach opens your donor database just as well.
Nonprofits make attractive targets for reasons you already know from the inside. Budgets rarely include a security line. There is often no IT staff at all, let alone a security team. The work runs on trust and email, and the inboxes handle money: gift acknowledgments, vendor invoices, grant disbursements.
The email side of the problem has been building for years. Abnormal Security's research, published in March 2025, found email attacks on nonprofits rose 35.2% year over year, with credential phishing, the kind aimed at harvesting your staff's logins, up 50.4%. Those stolen credentials feed the login-attack machine Okta is now measuring on the other end.
The report's second finding deserves as much attention as the first. Among larger nonprofits (those with more than 200 employees), 80% are already deploying or piloting autonomous AI agents. At the same time, 76% of nonprofits lack a formal AI strategy and 58% have no restrictions on which AI tools staff can use.
That combination has a predictable failure mode. Staff sign up for free AI tools with a work email and a password, outside your single sign-on (SSO, the setup where one managed login grants access to all your apps) and outside multi-factor authentication (MFA). Every one of those accounts is a new door with a cheap lock, and IT cannot patrol doors it does not know exist.
Okta's data also shows nonprofits ranked last among all 16 industries it tracks for automated lifecycle management, the discipline of automatically shutting off accounts when someone leaves. Adoption is growing, Okta notes, but from the back of the pack. In a sector that runs on short-tenure staff, seasonal workers, and volunteers, orphaned accounts are not an edge case. They are standing inventory for attackers.
None of this requires a security budget you do not have. It requires four decisions, roughly in this order.
First, turn on MFA for every account that touches money or donor data, starting with email, your CRM, and your bank. CISA's guidance walks through the setup, and its MFA hierarchy puts phishing-resistant methods at the top and text-message codes in the weakest tier, with authenticator apps in between. Passkeys and hardware keys, the FIDO methods CISA names as the strongest, are that top tier; Okta says its own passwordless login method, FastPass, grew 98% year over year, a sign the sector is starting to move that way.
Second, write down who has an account where, and kill what is orphaned. A one-hour audit of your email admin console, CRM user list, and bank access beats any tool you could buy. Make deactivation part of the offboarding checklist the same day someone leaves.
Third, give staff a sanctioned path for AI tools instead of a ban they will route around. A one-page policy naming which tools are approved, what data can never be pasted into them, and requiring work accounts behind SSO where possible closes most of the shadow-AI gap.
Fourth, use the free help. Microsoft's nonprofit security program includes a free security assessment and discounted security licenses once you validate your nonprofit status through its nonprofit program. If you have already set up email authentication to protect the messages you send, this is the matching work on the accounts you hold. And the same access review pairs naturally with the donor data cleanup worth doing before year-end anyway.
Okta's numbers describe its own customers, but the direction is unambiguous: attackers have concluded that nonprofit logins are the softest way in, and hostile attempts have gone from background noise to a majority of login traffic in two years. The response does not take a security team. MFA on everything that matters, a same-day offboarding habit, a sanctioned list of AI tools, and the free assessment from a vendor you already use will put you ahead of most of the sector. The login page is the front door now. Lock it like one.
One email when new briefings publish. No noise, unsubscribe anytime.