They have a decent setup against DDOS - utilizing CloudFlare and WAF.
I'll cut them some slack on that - but they need to bring in outside professionals if they can't stem the attacks with their own staff.
Someone either penetrated Givesendgo to get the donor list or some lazy coding allowed the data to be scraped from the site.
Remember Crowdstrike? The outfit that claimed that Russia hacked the DNC servers? No, I am not recommending them. The DNC hired them and then the FBI kind of handed off the DNC investigation to them. They seem to have moved from DC to Austin.
Just because a website claims to help you set up security doesn't guarantee anything.