A cyber incident involving the CRM provider Beacon has potentially affected around 1500 UK charities, particularly those in healthcare and victim support sectors. Unauthorized access to personal data, including names, email addresses, telephone numbers, and donation records, has been reported. Beacon notified all its clients and confirmed that the data involved, while encrypted, may have been decrypted. The breach was attributed to a compromised access key.
No sensitive patient information or payment details were involved, but charities are urged to notify the UK’s Information Commissioner’s Office. The incident highlights the cyber vulnerability of charitable organizations, which might be targeted due to their perceived low investment in cybersecurity.