Information relating to Beacon CRM cyber-incident
Beacon CRM, the system that Break use for managing our supporter and contact data, was recently affected by a cyber-security incident. Beacon is used by over 1,000 charities as their CRM, who have all been affected by the incident.
Their current understanding is that compromised credentials were used to gain access to Beacon, and encrypted copies of their database backups were made. Beacon are still in the process of investigating and have not yet been able to confirm if the encrypted information has been downloaded.
Based on the information currently available, we believe the personal information of our supporters and contacts may have been included in data affected by this incident. This may include names, email addresses, postal addresses and phone numbers. We are taking this matter very seriously and are working closely with Beacon to monitor and confirm the impact. We would like to reassure that financial information was not affected. There is currently no evidence that this data has been shared publicly, published online or otherwise misused.
Beacon has implemented immediate measures to secure its systems and prevent further unauthorised access.
What does this mean for you?
As a precaution, we are making everyone on our database aware of the incident so that they can remain vigilant and take extra care with any unexpected emails, text messages or phone calls requesting personal information. To help with this, we recommend reading the National Cyber Security Centre’s guidance.
We are very sorry for any concern this may cause. If you have any questions or concerns, please don’t hesitate to get in touch via communications@break-charity.org.
FAQs
Based on the information currently available, information held about our supporters and contacts within Beacon may have been affected. This could include names, email addresses, postal addresses and telephone numbers.
At this stage, Beacon's investigation is ongoing and we are continuing to work with them to understand exactly what information may have been impacted.
Protecting the personal information of our supporters, donors and contacts is extremely important to us. Since being notified of the incident, we have:
- Worked closely with Beacon to understand the nature and potential impact of the incident
- Reviewed the information that may have been affected
- Assessed the potential risks to individuals whose information we hold
- Considered our obligations under data protection legislation, and notified the Information Commissioner's Office (ICO)
- Continued to monitor developments as Beacon's investigation progresses.
We are not currently aware of any misuse of personal information as a result of this incident. However, as a precaution, we recommend that you:
- Be cautious of unexpected emails, phone calls, text messages or social media messages
- Avoid clicking on links or opening attachments in communications you were not expecting
- Never share passwords, security codes or financial information in response to unsolicited requests
- Verify any request for personal information by contacting the organisation directly using contact details from its official website.