Beacon CRM provides specialist support to the UK’s third sector.
A business providing specialist customer relationship management (CRM) software to Britain’s third sector has reported itself to regulators over a cyber attack.
Beacon CRM has warned it may never know the extent of the incident, which took place earlier this month.
On 3 August, Beacon informed their customers of a cyber security incident involving unauthorised access to copies of customer database backups.
Many Scottish charities use Beacon CRM to manage relationships with donors, supporters, volunteers, and beneficiaries.
The provider’s website boasts of being the “top-rated CRM built especially for charities”, inviting charities to “breathe a sigh of relief”, adding: “More than a thousand charities trust Beacon to run their organisations like clockwork.”
Beacon has now reported itself to the Information Commission’s Officer as well as to other relevant authorities.
In a statement following the incident, Beacon said on its website: “We recognise it has been a frustrating time for our customers as we sought to get further detail on what happened and we apologise that a lot of your questions have gone unanswered. This is because we just didn’t have the information to give to you – indeed, we might never know some of the answers we seek.
“We did not want to speculate before the findings had been sufficiently verified, but we recognise that the limited information available until now has been frustrating.
“We greatly appreciate all the patience you have shown us so far. We know this can’t have been easy.”
A spokesperson for the business added: “We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.
“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”
Beacon says their investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party, warning that it is highly unlikely they will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution.
Charities have been to told to “assume that all data that you store in Beacon, including attachment files, has been downloaded”.
Beacon also said its experts have advised that based on the available evidence it is possible the unauthorised third party responsible for this incident would have been able to decrypt it before copying it from our systems.
Since containing the initial incident, Beacon’s team has not identified or observed any ongoing unauthorised access” to Beacon’s systems.
Cyber experts from the Scottish third sector have provided advice to those affected, and also to other charities who wish to check their own systems.
SCVO’s cyber resilience co-ordinator Alison Brogan said while investigations continue, there are some practical steps organisations should take now.
She wrote: “Even if you’re not a Beacon CRM customer, these principles will help you respond should an incident affect one of your suppliers.
“If you have a data breach procedure, incident response plan or data protection policy, now is the time to use it.
“Ensure there is a clear lead within your organisation coordinating activity, gathering information, and communicating with the supplier, trustees, regulators, and staff as required. Keeping records of decisions and actions taken will also be important.
“Every charity uses its CRM differently. The most important question is not simply whether your organisation uses the affected system but what information was stored within it.
“This incident is a reminder that charities increasingly rely on third-party suppliers to store and process important information.
“Cyber incidents can be unsettling, but a calm, structured response focused on understanding the risks and protecting the people you support is the best way forward.”
Charities across Scotland are responding following the news.
In a statement, one of the CRM’s users who provide a testimony on the Beacon website, Edinburgh Dog and Cat Home shared a statement on the incident.
They wrote: “Beacon has advised us that compromised credentials were used to gain unauthorised access to its systems and copies of database backups were made. Beacon has engaged external cyber-security specialists and is continuing to investigate the incident.
“The information we hold in Beacon does not include payment details or special category personal data, such as information relating to racial or ethnic origin or sexual orientation.
“Beacon has advised that it is unlikely to be possible to establish exactly which information was downloaded or who it relates to. We are therefore taking a precautionary approach and treating all data held in Beacon as potentially affected.
“We take the security and privacy of personal information extremely seriously. We have reported the incident to the Information Commissioner’s Office (ICO) and have taken steps to protect the information we hold.
“We are contacting individuals who are potentially impacted and will provide further updates when we have more information.”
Others have also confirmed that they are assessing how they have also been affected by the breach.
The Scottish Commission for People with Learning Disabilities said: Although we have no evidence that any personal information has been accessed or misused, we are taking a precautionary approach and are assuming that information held in our Beacon database may have been affected.
“The information held in Beacon varies depending on an individual’s relationship with SCLD.
“For most people, this is likely to include contact information such as your name, email address, organisation and, where relevant, your telephone number.
“For some people, we may also hold additional information to help us support your involvement with SCLD. This could include your postal address, date of birth and information about your support needs.
“We do not store bank details or payment card information in Beacon.
“As soon as we were informed of the incident, we began reviewing the information we hold in Beacon and assessing the potential impact on the people whose information we store.
“We have assessed the incident in line with UK data protection requirements. We are also reviewing the information we hold within Beacon and our processes for managing personal information.
“At this stage, there is no evidence that your personal information has been misused. We understand that news like this may be concerning and we are very sorry that this has happened.”
Cyrenians said it may be impossible to tell which organisations have been affected.
“It is highly unlikely that we will ever be able to know for sure whether Cyrenian’s data was affected,” they wrote.
“At this stage, Cyrenians has no evidence that any personal information relating to our clients, supporters, donors, volunteers or partners has been misused.
“However, given the information provided by Beacon, we are treating this incident with the utmost seriousness and are acting on the basis that data held within the platform may have been affected.
“As a precaution, we encourage everyone to remain vigilant for unexpected emails, phone calls, text messages or other communications requesting personal, financial or security information. If you receive any communication claiming to be from Cyrenians which seems unusual or suspicious, please contact us directly before responding.”
Glasgow-based PEEK, MCR Pathways, the Scottish Women’s Institutes, and the Environmental Rights Centre for Scotland have also all confirmed that they have been affected.
The Charity Commission has confirmed it is aware of the situation and working with others to monitor the impact.
They said in a statement: “We appreciate the concern this incident will have caused to the charities affected and their supporters.
“Given the nature of this incident and the number of charities that may be affected, the Commission has been actively monitoring the situation and is in contact with the Information Commissioner’s Office (ICO), as the lead regulator for upholding information rights and data protection law in the UK.
“A number of affected charities have submitted serious incident reports to the Commission and we encourage trustees to continue to follow our guidance on serious incident reporting. This requires you to report incidents which results in or risks significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation.
“Due to the volume of such reports expected on this matter alongside other incoming reports, it is likely to take longer than usual for the Commission to respond. We appreciate your patience and understanding as we prioritise instances of the greatest risk.”
