Charities’ data held by the customer relationship management company Beacon CRM has “likely” been downloaded by an unauthorised third party following a cyber-security incident.
Beacon CRM, which according to its LinkedIn profile supports more than 1,500 charities, became aware of the breach on Wednesday last week.
The company told customers about the breach on Monday, saying its understanding was that “compromised credentials were used to gain access” to its data.
Copies of its database backups were made during the breach, the company said, with evidence suggesting these were likely downloaded.
“Whilst the exfiltration (copying or taking) of this data from our system hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded,” said Charlie Gregson, head of commercial at Beacon CRM.
Gregson said that following containment actions, Beacon was “secure and available to our customers to use as normal”, adding that it had not experienced any service interruption as a result of the breach.
On an incident page on its website, Beacon CRM added: “There is currently no evidence that this data has been shared on the dark web and there has been no ransom request.”
The company said it had implemented “immediate measures” to secure its systems and prevent further unauthorised access.
These include a “thorough forensic investigation” with external cyber-security experts to understand what happened; working with law enforcement and regulators as required; conducting online monitoring; and completing precautionary security measures, the company said.
Beacon CRM urged affected charities to consider whether the incident met the threshold for reporting to the Information Commissioner’s Office, adding: “A personal data breach should be reported to the ICO unless it is unlikely to result in a risk to the rights and freedoms of individuals.
“Whether there is a risk will depend on the nature of the data that was stored in Beacon, and so will vary from organisation to organisation.”
The company added that the threshold for notifying affected individuals directly was higher than this, meaning charities only needed to inform individuals if there was “likely to be a high risk to their rights and freedoms”.
A number of organisations have already alerted their audiences about the breach, including the Institute for Voluntary Action, in an email seen by Third Sector, and the English National Ballet, according to the BBC.
Beacon CRM said it was expecting a significant amount of contact and had assigned extra resources to answer questions, but it expected this to take “longer than usual”.
A spokesperson for the ICO said: “We are aware of an incident at Beacon CRM and have received a number of reports from impacted organisations. We are assessing the information provided and considering our next steps.
“Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms.”
The spokesperson added that if an organisation has been affected by the incident, they should use the ICO’s self assessment tool to consider risk and use its online tool to report a breach if necessary.
