Âé¶¹Éç

Beacon Data Breach Information

Information about the recent Beacon Data Breach

You may have read or come across news of the Beacon CRM data breach. This is a system Âé¶¹Éç Foundation use in our fundraising department, but we are in a position whereby we have been able to identify exactly which of our supporters could be affected by this data breach.

Anyone who may have been affected has already received a letter from our CEO,  therefore if you have not received a letter your personal data is not affected. 

We are posting the letter below as well, but again, if you haven’t already received this then your data has not been affected.

 

Please direct any questions to [email protected]

Dear Supporter,

I am very sorry to inform you that we have been notified of a cybersecurity incident by Beacon, the fundraising database provider we use at The Âé¶¹Éç Foundation to store and manage contact information about you and our other supporters. We are writing to you as we have been able to identify a small number (5%) of our supporters who have been impacted. If you are receiving this letter it’s because your details were part of that data breach.

Beacon has informed us that their systems were accessed by an unauthorised third party using compromised credentials, and that copies of database backups have been downloaded. Beacon is working closely with specialist cybersecurity experts, law enforcement and relevant regulators to understand exactly what happened and what measures they need to put in place to prevent recurrence.

At present, Beacon has found no evidence that any information linked to this incident has been published online.  However, Beacon has advised us that the incident is likely to involve data the Foundation stores within its system. This information typically includes names, contact information and preferences, and the donation and engagement history of our supporters.

We would like to reassure you that the Foundation does not store financial details within Beacon. Donations to the Foundation are processed through specialist payment providers and, based on the information currently available, there is no evidence of an increased risk of financial fraud following this incident.

We recognise the trust you place in us when you share your information, and we take our responsibility to protect it very seriously. We are committed to maintaining the highest standards of security and privacy. We use Beacon because they hold the UK’s highest level of cyber security qualification. This is a criminal incident, and we are working closely with Beacon and have reported the breach to the relevant regulators.

What you should do

As a sensible precaution, we recommend remaining alert to unexpected emails, text messages or phone calls asking for personal or financial information. If you receive any communication claiming to be from the Âé¶¹Éç Foundation that you are unsure about, please contact our Fundraising team directly (Monday to Friday, 9am to 5pm) at [email protected] or by telephone on 0191 212 7878.

I understand that news like this can be worrying. I am deeply sorry for the concern and inconvenience this incident may cause you. I recognise the trust you place in us and take our responsibility to protect your information extremely seriously.

Your support makes our work possible, and protecting your information is fundamental to the relationship we have with you. We will continue to monitor the situation closely and take any action necessary to protect you and our other supporters. If you have any questions or concerns, please do not hesitate to get in touch.

 

Yours faithfully,

John Preston

Chief Executive