Skip to main content

Charities hit by data breach involving software provider

At least two Guernsey charities have been hit by a data breach involving a UK software provider.

‘Should a Guernsey charity or organisation become aware that they have been compromised by the breach, we would remind them of their obligations to report such incidents to our office,' said data protection commissioner Brent Homan.
‘Should a Guernsey charity or organisation become aware that they have been compromised by the breach, we would remind them of their obligations to report such incidents to our office,' said data protection commissioner Brent Homan. / Sophie Rabey, Guernsey Press

A cyber security incident involving Beacon CRM, which helps charities manage donors and track fundraising, is believed to have affected more than 1,000 organisations, including at least eight in Jersey.

Beacon CRM said the breach was due to an unauthorised third party gaining access through a ‘compromised access key’ and admitted that ‘copies of database backups were made and likely downloaded by the unauthorised third party’.

Guernsey’s Data Protection Authority confirmed on Friday that it had received two breach incident reports from Bailiwick-based charities relating to the Beacon breach.

‘We have been in contact with our Crown Dependency counterparts as we continue to monitor developments,’ said data protection commissioner Brent Homan.

‘Should a Guernsey charity or organisation become aware that they have been compromised by the breach, we would remind them of their obligations to report such incidents to our office.

‘In addition to assessing the impact of such incidents, our office will often provide actionable advice on notification obligations and how to mitigate risks stemming from a breach.’

A Beacon spokesman said: ‘We acted quickly to identify the threat and contain it, and Beacon is operating normally.

‘We are currently investigating the full circumstances of the incident with external cybersecurity specialists, but our current understanding is that a compromised access key was used to gain access to Beacon.’

People who have donated to charities have been warned to take precaution with any unexpected calls, emails or texts, particularly in terms of clicking links, making payments or sharing personal information.

The UK charity Heartbeat, which has a long-standing connection with Guernsey, providing accommodation for Bailiwick residents in the charity’s 24-bedroom Heartbeat House since its founding 32 years ago, is one of the organisations which uses Beacon’s CRM system to store information about its supporters.

‘Beacon has informed us that it experienced unauthorised access to its systems and this incident is likely to have affected the data we store within the CRM,’ it said.

‘Beacon’s investigations are ongoing, but please rest assured that Heartbeat is doing all we can, together with the Information Commissioners Office, to minimise any risks.’

It said the information that could potentially have been affected included people’s contact details, donation history and communication preferences, but it reassured its supporters that it did not store bank account numbers, sort codes, full payment card numbers or card security details within Beacon.

You need to be logged in to comment.