A massive cyberattack may have compromised sensitive information across the UK charity sector. The attack targeted Beacon CRM, a secure database system used by many organizations to manage their operations. While the extent of the damage remains unclear, many charities have reportedly been affected. This includes Gambling with Lives, one of the UK’s leading gambling harm prevention organizations.
Critical Payment Details Have Not Been Exposed
According to Beacon, a malicious third party obtained compromised credentials and accessed its systems. Early evidence suggests that the perpetrators downloaded database backups. While such data is usually encrypted, the company warned that it is not fully safe and may be recovered. The full extent of the breach remains unknown.
The cyberattack was reportedly discovered on July 29. Beacon has already reached out to all its customers and is actively supporting them. Fortunately, password and payment details do not appear to have been exposed, though the company recommends caution. The Information Commissioner’s Office, the Charity Commission and the Gambling Commission have also been notified of the incident.
We recently experienced a cyber-security incident that involved unauthorized access to Beacon systems containing data we process on behalf of our customers.
Beacon CRM statement
Beacon has taken steps to shut down the vulnerability and is working with cybersecurity experts to prevent future breaches. Over 1,500 charities depend on the company’s CRM software, so the full extent of the breach will become clear in the next few days. Fortunately, Beacon’s services were not affected during the incident, avoiding disruptions for charities.
The Situation Continues to Evolve
This incident has reportedly affected some of the UK’s leading gambling-related charities such as Gambling with Lives. The organization provides support to families affected by gambling harm and raises awareness about problem gambling. It also hosts community events, assists with investigations, and campaigns for stricter regulations on gambling advertising.
According to a recent Next.io report, the charity is fully aware of the incident and has warned its staff to exercise caution with official correspondence. The compromised information could include names, birth dates, contact details, and donation records. Gambling with Lives is also actively monitoring the situation but remains confident that the incident will not affect its day-to-day operations.
We’ve already spoken with all our customers and our focus now is on supporting them as much as possible regarding potential data impact.
Beacon CRM statement
While the gambling sector has been a frequent target of cyberattacks, charities are now apparently also on the radar. Disregarding the morality of targeting an organization that helps vulnerable individuals, charities often process significant amounts of money, making them attractive to hackers. External partners that service multiple clients, such as Beacon, are also especially vulnerable, necessitating stronger safeguards and constant vigilance.
