Beacon CRM confirmed it was the target of a cyberattack that resulted in the exposure of data belonging to a significant number of UK charities.
The company, which provides CRM software to over 1,500 charities, is conducting an ongoing investigation into the incident. Beacon is advising its users to assume that all data stored on its platform may have been compromised and downloaded by the unauthorized third party, based on information published by The Register.
The investigation by Beacon CRM indicates that database backups were copied and likely downloaded. While the company stated that customer data is encrypted, it warned that the attackers may have been able to decrypt it, meaning the copied information could be readable.
Early evidence suggests compromised credentials were used to gain access to Beacon's systems. The attack appears to have been discovered on July 29, with affected customers being notified starting Aug. 3. Among the confirmed victims are the Molly Rose Foundation, The Upper Room, Chiswick House and Gardens Trust, Macmillan Cancer Support Jersey, Motiv8, and UK-Med. Victim Support stated that no victim data was affected.
Beacon has reset all user passwords and implemented stronger password requirements as a precautionary measure. The full extent of the data breach and the specific types of sensitive information compromised are still being determined, but the incident highlights a significant risk to the UK charity sector.
Source: The Register
Written by
Kelley Damore
Chief Content Officer
CyberRisk Alliance
Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.