TL;DR: On July 7, 2026, the Interlock ransomware group claimed the YMCA of Western North Carolina on its dark-web leak site, alleging exfiltration of roughly 330 GB of data including client and employee records. The Asheville-headquartered nonprofit is the state's largest provider of licensed school-age childcare and runs seven fitness centers, a summer camp, and dozens of food trucks across western North Carolina. If Interlock can hit an organization with a real IT function and a real budget, thousands of smaller NC nonprofits without one need a defensible plan by Q4 2026.
Key takeaway: Nonprofits were Interlock's second-most-hit sector in Q2 2026, and North Carolina's Identity Theft Protection Act (N.C.G.S. Section 75-65) treats a stolen donor spreadsheet the same as a stolen credit card table. The organizations most exposed are the ones that assume "we are too small to matter" and "we already have an IT guy." Neither is a control.
Worried your nonprofit is the next headline? Contact Preferred Data Corporation at (336) 886-3282 for a nonprofit-focused security review. Serving Asheville, High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987, from 1208 Eastchester Drive, Suite 131, High Point, NC 27265.
What happened to the YMCA of Western North Carolina?
On July 7, 2026, the Interlock ransomware group listed the YMCA of Western North Carolina on its Tor-hosted leak site, claiming exfiltration of approximately 330 GB of internal data. Independent incident briefs from DeXpose and Hookphish reported that the stolen data set included client and employee information.
The YMCA of Western North Carolina, founded in 1889 and headquartered in Asheville, operates seven fitness centers across Buncombe County, Henderson County, and surrounding western North Carolina communities, and is the state's largest provider of licensed school-age childcare. An incident at that scale touches donors, members, employees, camp families, and thousands of children whose records fall under heightened privacy expectations.
At the time of writing, the YMCA has not published a full disclosure of scope, and no ransom payment has been publicly confirmed. What is confirmed is a three-track problem every ransomware victim faces: technical recovery, regulatory notification under the NC Identity Theft Protection Act, and rebuilding donor trust in a brand that has served the region for 137 years.
Who is Interlock and why should an NC nonprofit care?
Interlock is a ransomware-as-a-service operation that surfaced in late 2024 and became one of the most active double-extortion crews of 2025 and 2026. CISA, the FBI, HHS, and MS-ISAC published a joint advisory as AA25-203A on July 22, 2025, updated through 2026, warning that the group targets North American businesses and critical infrastructure.
Nonprofits should care for three specific reasons. First, tracking by Ransomware.live put nonprofits in Interlock's top three sectors in the first half of 2026, behind only professional services and healthcare. Second, Interlock is a double-extortion operator: even if you pay to decrypt, exfiltrated data still gets leaked or sold. Third, the group's tradecraft is designed to succeed against exactly the environment most small nonprofits run: unmanaged endpoints, shared admin accounts, and no 24/7 monitoring.
For a nonprofit board in Asheville, Hendersonville, High Point, or Greensboro, the honest translation is that your organization is not too small or too mission-driven to be interesting. You are interesting because you are reachable, and because operators know a nonprofit board will feel enormous pressure to pay to protect donors and kids.
How does Interlock actually get in?
Interlock's initial access is dominated by social engineering, not exotic zero-days. The CISA joint advisory documents three recurring patterns: "ClickFix," a fake CAPTCHA or browser-update page that instructs a user to paste a command into the Windows Run dialog or PowerShell; a "FileFix" variant using a fake file-download prompt; and drive-by compromise from watering-hole sites tailored to the victim's industry.
Once inside, Interlock uses living-off-the-land techniques: legitimate Windows tools (PowerShell, WMIC, PsExec), abused remote-access utilities (AnyDesk, ScreenConnect, Splashtop), and standard Active Directory reconnaissance. Data exfiltration typically goes to consumer cloud-storage services like MEGA that blend into normal traffic most nonprofit firewalls do not inspect. Encryption then deploys on both Windows and Linux hosts, hitting file servers, backup targets, and virtualization hosts in the same run.
The takeaway is that this attack chain is stopped not by one silver-bullet product but by a small set of everyday controls: phishing-resistant MFA, blocked or monitored consumer cloud-storage domains, EDR with 24/7 monitoring, and immutable backups. Every one is achievable on a small nonprofit budget when engineered correctly.
What does a 330 GB nonprofit breach actually mean?
A 330 GB haul from a mid-sized nonprofit is not a spreadsheet or two. It is, in practical terms, everything the organization has stored in shared drives, email archives, and back-office systems for years: donor CRM exports with names, addresses, and giving history; employee HR files with Social Security numbers and I-9 records; member and program-participant rosters including minors in childcare and summer camp; volunteer background-check records; payment or bank-draft records for recurring donations; and years of internal email.
Each data class triggers different downstream problems. Donor PII creates notice obligations under the NC Identity Theft Protection Act plus roughly 50 additional state statutes. Employee W-2 and Social Security data creates IRS and state-tax notification obligations and often invites wage-based fraud within 60 days. Child-participant records create acute reputational and possible state-AG scrutiny. Cardholder data pulls in PCI DSS, the card brands, and the acquiring bank.
The financial damage dwarfs any ransom demand. IBM's Cost of a Data Breach report has for years pegged average per-record breach cost in the low hundreds of dollars; at a conservative $150 per affected individual, a nonprofit notifying 10,000 donors is looking at more than $1.5 million in notification, credit-monitoring, legal, and forensic spend before the first dollar of lost donations.
What does the NC Identity Theft Protection Act require after a breach?
North Carolina's Identity Theft Protection Act, N.C.G.S. Section 75-65, requires any business including a 501(c)(3) nonprofit that owns or licenses personal information of NC residents to notify affected residents "without unreasonable delay" after discovery of a security breach. The NC Department of Justice consumer page is the plain-English starting point.
Three obligations bite hardest. First, if the breach affects 1,000 or more NC residents, the organization must notify the NC Attorney General's Consumer Protection Division and all consumer reporting agencies, in addition to affected individuals. Second, notice content is prescriptive: it must describe the incident, the data involved, protective steps taken, and toll-free numbers for the major credit bureaus. Third, failure to comply is treated as a violation of the state's Unfair and Deceptive Trade Practices Act (N.C.G.S. Chapter 75), which allows civil penalties and private rights of action.
For a nonprofit, the practical impact is that a ransomware incident is not "over" when the servers come back. The 30 to 90 days that follow are dominated by legal review, forensic scoping, drafting notification letters, standing up call-center support, and answering AG inquiries. Organizations with a written incident response plan, a pre-negotiated IR retainer, and cyber insurance survive that phase. Organizations that improvise typically do not.
Not sure whether your nonprofit could meet NC notification obligations tomorrow? Call Preferred Data Corporation at (336) 886-3282 for a 60-minute board-ready security posture review. On-site engagements available within 200 miles of High Point, covering Asheville, Charlotte, Raleigh, Greensboro, Winston-Salem, and the entire Piedmont Triad.
What five controls should every NC nonprofit have in place before Q4 2026?
The five controls that would have blunted the Interlock attack chain are the same five that make an NC nonprofit defensible against most ransomware operators active today. None are exotic or enterprise-only.
- Phishing-resistant MFA on every account, no exceptions. SMS codes are not enough; the goal is FIDO2 security keys or platform authenticators on Microsoft 365 or Google Workspace, plus MFA on every remote-access, banking, donor-CRM, and payroll portal. The CISA joint advisory lists MFA weakness as a top Interlock enabler.
- Managed EDR with 24/7 human monitoring, not just antivirus. A SOC watching alerts is what catches living-off-the-land activity at 2 a.m. on a Saturday. Static antivirus does not.
- Immutable, offline-verified backups tested monthly. Object-lock backups plus at least one offline copy, with a documented monthly restore test. If the only backup is a sync to the same cloud drive Interlock encrypted, it is not a backup.
- Blocked or monitored consumer cloud-storage and unauthorized remote-access tools. MEGA, personal Dropbox, unauthorized AnyDesk or ScreenConnect installs, and unmanaged file-sharing are the exfiltration highway. DNS filtering and application control shut most of them.
- A written, tested incident response plan with a retained IR firm. One page that names the incident commander, the IR firm on retainer, the cyber insurer's hotline, legal counsel, and the notification-letter template. Print it. Rehearse it once a year with the executive director and board chair.
Every one of these is achievable inside a $500,000 nonprofit operating budget, and every one is required to make a good-faith case to a cyber insurer, the NC AG, or a donor asking "what were you doing to protect my data?"
What can an NC nonprofit actually afford?
Nonprofit boards do not need to guess. The framework below maps realistic monthly spend to organization size, based on typical NC managed-service pricing for 2026, assuming Microsoft 365 Business Premium or Google Workspace Business Plus as the identity anchor.
| Control | Small (10-25 staff, ~$500K-2M budget) | Mid-sized (25-100 staff, ~$2M-10M) | Large (100+ staff, $10M+) |
|---|---|---|---|
| Phishing-resistant MFA (M365 Business Premium) | Included, ~$22/user/mo | Included, ~$22/user/mo | Included + conditional access |
| Managed EDR with 24/7 SOC | $8-14/endpoint/mo | $8-12/endpoint/mo | $6-10/endpoint/mo at volume |
| Immutable cloud backup | $150-400/mo | $400-1,200/mo | $1,200-3,500/mo |
| DNS filtering + app control | $2-4/user/mo | $2-4/user/mo | $2-3/user/mo |
| Security awareness + phishing sim | $3-5/user/mo | $3-5/user/mo | $2-4/user/mo |
| Managed IT + vCIO oversight | $1,500-3,500/mo | $3,500-9,000/mo | $9,000-20,000/mo |
| Written IRP + annual tabletop | $1,500-3,000/yr | $3,000-7,500/yr | $7,500-15,000/yr |
| Cyber insurance premium | $2,500-6,000/yr | $6,000-25,000/yr | $25,000-100,000/yr |
For a 40-staff nonprofit in Asheville, Greensboro, or Charlotte, that translates to roughly $2,500 to $5,500 per month in security-specific spend, plus baseline IT. A comparable ransomware event costs a mid-sized nonprofit low seven figures once notifications, credit monitoring, forensics, downtime, and donor attrition are counted, per years of IBM Cost of a Data Breach benchmarks. The math is not close.
Ready to build a nonprofit-appropriate stack? Contact Preferred Data Corporation at (336) 886-3282 or visit 1208 Eastchester Drive, Suite 131, High Point, NC 27265. BBB A+ rated, in business since 1987, 100+ active clients, 20+ year average client tenure. On-site support anywhere within 200 miles of High Point, from the Piedmont Triad to Asheville to the coast.
Frequently Asked Questions
We are a small church, chamber of commerce, or food bank. Are we really a target?
Yes. Interlock and its peers target reachable organizations, not famous ones. Ransomware.live tracking through the first half of 2026 puts nonprofits, faith organizations, and community associations in the top five most-hit sectors nationally, largely because they run unmanaged endpoints and no 24/7 monitoring. If your organization holds donor PII, employee records, or payment data, you fit the profile.
We use Microsoft 365 or Google Workspace. Isn't that "enough"?
No, but it is a good starting anchor. Both platforms have strong native security controls (conditional access, Advanced Threat Protection, native MFA), but only in the right SKU and only when configured. A default Business Basic tenant with SMS-based MFA and no backup is not defensible. The same tenant upgraded to Business Premium, hardened per CIS benchmarks, backed up to an immutable third-party store, and monitored by a SOC is a different animal.
We do not accept credit cards. Do NC breach laws still apply to us?
Yes. The NC Identity Theft Protection Act applies to any personal information of NC residents, defined broadly to include Social Security numbers, driver's license numbers, financial account information, and other identifiers. A stolen donor mailing list with names and emails alone may not trigger the statute, but the moment SSNs (HR files) or bank-draft data (recurring giving) are involved, notification obligations apply.
What are the IRS requirements around safeguarding donor and staff data?
The IRS publishes Publication 4557, Safeguarding Taxpayer Data, which lays out a written information security plan requirement for anyone handling taxpayer data. Nonprofits that issue W-2s, 1099s, and donor tax receipts hold the same underlying data and face the same threat model. A written information security plan aligned to Publication 4557 is table stakes for any nonprofit board's fiduciary duty.
Does our D&O or general-liability insurance cover a ransomware payout?
Almost never. D&O covers wrongful acts by directors and officers; general liability covers bodily injury and property damage. Ransomware losses, business interruption, forensic costs, and breach-notification expenses require a dedicated cyber insurance policy, and 2026 underwriting requires evidence of MFA, EDR, backup, and security awareness training before a policy issues. Treat the cyber application itself as a security-maturity checklist.
Can we get grants or discounts to fund nonprofit cybersecurity?
Yes. TechSoup, various NC nonprofit capacity-building programs, and vendor-specific offerings (Microsoft Nonprofit, Google for Nonprofits, several EDR vendors) offer meaningful discounts on core security tooling. Microsoft 365 Business Premium is dramatically discounted for eligible nonprofits and includes MFA, conditional access, and Defender protections. A nonprofit-experienced MSP should build the stack around available discounts, not retail pricing.
We had an IT audit last year. Isn't that enough?
An audit is a snapshot; ransomware is a movie. An audit finding that MFA is enabled on 92 percent of accounts means Interlock only needs to find the other 8 percent. Continuous controls (EDR alerts, backup verification, log monitoring, phishing simulation) plus a documented remediation cadence are what turn an audit into a defensible security program.
Should we ever pay a ransom?
That is a decision for the board, legal counsel, cyber insurer, and law enforcement, not the IT team, and not one to make in the first 48 hours. FBI, CISA, and OFAC discourage payment, and OFAC sanctions can make payment to some groups illegal. Payment does not prevent leak of already-exfiltrated data, and roughly a third of paying victims never receive a working decryptor. Make this decision in a tabletop months before an incident, not at 3 a.m. on the day of one.