Beacon CRM hack exposes UK charity donor data, backups likely stolen

The charity CRM provider told customers to assume all stored data, including attachments, was downloaded.

CSBadmin
2 Min Read

Beacon CRM, a fundraising platform used by more than 1,500 charities, confirmed a cyberattack in which database backups were copied and likely downloaded. The company warned customers to assume everything stored on the platform, including attachment files, was taken, and that encrypted data may have been readable by the attackers.

Beacon suspects stolen credentials played a role and advised anyone who opened a paid account or free trial before July 27 to assume every piece of data in the platform was compromised. Every user was forced to choose a new password, with stricter rules for what replacements had to meet. A charity caught up in the incident said Beacon learned of the breach on July 29, while the Molly Rose Foundation only received notice on August 3.

Confirmed victims include the Molly Rose Foundation, English National Ballet, Chiswick House and Gardens Trust, UK-Med, Motiv8, and Macmillan Cancer Support Jersey. Affected data spans names, addresses, emails, phone numbers, genders, dates of birth, and donation records. The Scottish Council for Voluntary Organisations cautioned that the platform is widely used by charities across Scotland.

The incident compounds a grim month for the UK charity sector. CAF Bank, owned by the Charities Aid Foundation, kept online banking offline for more than ten days after detecting attempted fraudulent activity on July 21 and a second, related incident targeting user logins on July 25. The bank reopened the service August 4 but warned of further outages, waiving monthly account charges for August and September.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.