New details are emerging about the scale and potential impact of the cyber incident affecting Beacon CRM, with charities warning that information ranging from supporter contact details to sensitive health records may have been caught up in the breach.
What happened in the Beacon data breach?
Beacon provides customer relationship management (CRM) software to more than 1,500 charities and voluntary organisations.
When the incident was first reported, Beacon said copies of customer database backups had been made and were likely to have been downloaded after an unauthorised third party gained access using compromised credentials.
The position has since become clearer.
On 12 August, Beacon told customers that its investigation had confirmed a copy of the database containing customer data, including attachment files, had been made and was likely downloaded in a readable format.
Some affected organisations have subsequently warned supporters to assume information they stored within Beacon could have been accessed.
Sensitive health information may be among the data affected
One of the most concerning developments involves Manchester-based HIV charity George House Trust.
The charity provides support, advice and information to people living with HIV. It has told people using its services that personal and sensitive health information may have been downloaded during the Beacon breach.
Information potentially involved includes home addresses, email addresses, telephone numbers and notes and records relating to people’s engagement with the charity. George House Trust has said there is currently no evidence that the information has been published or misused.
The development shows why the impact of the Beacon incident may be very different from one charity to another.
More charities confirm they are affected
A growing number of charities have now contacted supporters about the incident.
The Molly Rose Foundation, which campaigns on suicide prevention and online safety, has confirmed that information stored within its Beacon system may include names, addresses, contact details, gender, dates of birth, donation or payment records and information supplied in connection with its services and activities.
Other organisations that have disclosed that they are affected or potentially affected include the Scottish Refugee Council, Bristol Mind, English National Ballet and a number of smaller charities across the UK. The Robert Burns Ellisland Trust has also warned members and donors that contact details and information about payments or donations were held within the affected system. It stressed that Beacon did not hold any card payment details.
This is not necessarily a complete list. If your charity isn’t named, that doesn’t automatically mean its information was unaffected.
What does this mean if your information was held by a charity?
If a charity has contacted you about the Beacon breach, read its notification carefully. It should explain what information the organisation believes may have been affected and whether there are any specific steps you need to take.
There is currently no evidence that the information taken in the breach has been publicly released or misused. However, stolen personal information can potentially be used to make phishing emails, scam calls and other fraudulent approaches more convincing.
You should be particularly cautious about unexpected messages that appear to come from a charity you support or have used. Avoid clicking unexpected links or opening attachments, and never provide passwords, verification codes or financial information in response to an unsolicited message.
If something does not look right, contact the charity directly using contact details from its official website rather than replying to the message.
Find out how to stay safe following a data breach in our handy guide.
Why sensitive information makes this breach particularly concerning
Not all personal information carries the same level of risk. Details such as someone’s name and email address can be useful to scammers, but information about a person’s health, circumstances or use of support services can be much more sensitive.
Health information is classed as special category data under UK data protection law and receives additional protection.
That matters in cases such as George House Trust, where records may reveal not simply that someone interacted with a charity, but potentially highly private information about their health and personal circumstances.
The consequences of that information being exposed could therefore go well beyond the risk of receiving unwanted emails or scam messages.
Could people affected by the Beacon breach claim compensation?
A data breach does not automatically mean that someone is entitled to compensation.
Whether a claim is possible will depend on the individual circumstances, including what information was involved, whether an organisation breached its data protection obligations, and whether the person suffered financial loss or distress as a result.
For people whose particularly sensitive information may have been exposed, the impact could potentially be more serious.
The investigation into the Beacon incident is continuing.
At Join the Claim, we’ll continue to follow developments as more charities establish what information was affected and the wider consequences of the breach become known.
Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.