NG Solution Team
Cybersecurity

Beacon CRM breach exposes supporter data at 1,000+ nonprofits

A cybersecurity breach at Beacon CRM has exposed the personal data of supporters at more than 1,000 nonprofits, including several prominent Christian ministries. Christians in Sport, Keswick Ministries, Kintsugi Hope, Langham Arts, Living Out, Operation Mobilization (OM) and ReSource have all notified supporters and donors about the incident.

Beacon CRM, based in the United Kingdom, said it detected unauthorized access to its systems and that supporter data was likely downloaded by a third party on July 29. The company notified its customers on August 3.

The leaked data may include names, phone numbers, email addresses and residential addresses, Beacon said. It added that no payment details were compromised and that it is unlikely to determine precisely what other data the hacker accessed.

Beacon CRM response and security claims

A Beacon CRM spokesperson said: “We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact.” Beacon said it has hired outside experts to investigate and mitigate the breach and that customers can continue to access the system as normal.

Beacon described its safeguards as “ironclad security features,” including private cloud hosting, real-time monitoring and ISO 27001:2022 certification. Fundraising Magazine has ranked Beacon the No. 1 CRM software provider for seven consecutive years and gave it a 4.7 out of 5 rating in its security index.

Advice for supporters and actions by affected organisations

Affected organisations have urged supporters to be alert for suspicious messages — particularly those requesting personal or payment information, claiming changes to payment or account details, or containing unfamiliar links or attachments.

Operation Mobilization UK wrote to supporters: “Based on the information currently available, we have no evidence that credit card, bank account information and any other financial details have been misused. … We also recognize that many Christian and non-Christian charities and their supporters have been affected too. We invite you to pray for wisdom and for the safety of everyone involved.” OM said it is taking steps to protect supporters’ information and has notified the U.K.’s Information Commissioner’s Office.

Sheffield Hospitals Charity, a secular nonprofit also affected, told supporters: “At this stage, there is no evidence that supporter information has been published or misused, and we are not aware of any fraud or harm resulting from this incident.”

Related posts

Chandipura virus: Is Gujarat IMA warning about early detection?

Jessica Williams

What changes are coming to cloud data retention for closed security alerts?

Michael Johnson

Amgen cybersecurity breach exposes patient data, SEC filing says

James Smith

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy