Beacon CRM confirms cyberattack that may have exposed charity data
Beacon CRM disclosed that an unauthorized party copied database backups, potentially giving access to donor and supporter information for several UK charities.
Beacon CRM announced that a cyber intrusion resulted in copies of its database backups being downloaded by an unauthorised actor, with activity spikes indicating data exfiltration. Although the stored data is encrypted, the company warned that the attackers might have been able to decrypt it, meaning the information could be readable. In response, Beacon reset every user password and imposed stricter password rules.
Several charities that rely on the platform, such as the English National Ballet, the Molly Rose Foundation, The Upper Room, Chiswick House and Gardens Trust, Victim Support, Macmillan Cancer Support Jersey, Motiv8, UK-Med and others, have been alerted to the breach. One charity reported that personal details of supporters, donors and service users were among the exposed data. Beacon continues its investigation but has not disclosed how the attackers gained entry.
Why it matters
Charities' donor and supporter data may be vulnerable after a breach of a widely used CRM system.
In this story