UK charities count the cost of Beacon CRM cyberattack
Database backups likely stolen, potentially exposing donor, supporter, and service user details
A cyberattack targeting UK charities' data is under investigation by Beacon CRM, a software company that serves more than 1,500 customers in the charity sector. The breach may have exposed a significant amount of customer data, with copies of database backups reportedly copied and downloaded by unauthorized third-party actors. Beacon is advising affected users to assume that all data stored on the platform, including attachments, was downloaded without authorization.
While the company maintains that customer data is encrypted, it is possible that the attackers could have decrypted the information. Beacon has not disclosed specifics regarding the nature of the stolen data or the parties affected, other than indicating that the attack was first detected on July 29. The Scottish Council for Voluntary Organisations (SCVO) reported that many Scottish charities use Beacon CRM, highlighting the extensive impact of this security incident.
High-profile victims include the Molly Rose Foundation, which informed Beacon of the breach on August 3, and homeless charity The Upper Room. English National Ballet, a customer of Beacon CRM, has also been affected, though they have not confirmed if their data was directly compromised. Beacon is implementing enhanced security measures, including password resets and stricter password requirements, to protect its users' information.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
Also reported by 1 other outlet
- UK charities count the cost of Beacon CRM cyberattack theregister.com