On Monday 3 August we were informed by the provider of our customer relationship manager system (database) – Beacon CRM – of a data breach to their system. This breach is believed to relate to the contact information of our members and supporters, along with the members and supporters of over 1,000 other charities that use this system.
This breach was directed at Beacon CRM and, as one of the leading providers of charity CRM, we know this will impact many of us in the charity sector.
As soon as we were informed our team at Berkshire MS Therapy Centre actioned measures as outlined in our policy and process, and following the guidance shared by Beacon.
We have also reported this incident to the ICO and the Charity Commission.
We do not as yet know the full details surrounding the breach, and the extent of data impacted. We did not however, store any bank or card details on the system so are confident this will not be a factor to consider. We have been reassured that no demand for ransom has been made and no information is on the dark web. We are awaiting further information from our provider to confirm any final details concerning the extent of the breach and level of data accessed.
Yesterday (4 August), a spokesperson from Beacon said, “We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.”“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”
Here at the Centre, we are deeply sorry for this breach, and although this was via one of our providers, we can only apologise for the distress this may cause to our members and supporters. We take our data protection and cyber security very seriously and will be reviewing our process and policy to ensure everything is as robust as possible.
This sort of incident is unfortunately becoming a feature of modern life. No matter how much security infrastructure and expertise are in place, cyber criminals are increasingly sophisticated in their tactics. We are incredibly saddened that a charity system in particular has been targeted in this way – and we can only hope that this does not destroy the trust and reputation of so many organisations working in very difficult times. We thank you all for your understanding and patience and hope we can rely on your continued support.
If you have any concerns or wish to discuss further then please contact the team on ms@bmstc.org
