Decoding the world of cybersecurity

Beacon breach exposes charity data backups

Beacon says compromised credentials were used to copy customer database backups, which investigators believe were probably downloaded.

Beacon breach exposes charity data backups
Summary
  • Beacon discovered temporary unauthorised access on 29 July and notified customers on 3 August.
  • Compromised credentials were used to create copies of database backups that were probably downloaded.
  • Exposure differs by charity because each organisation determines which supporter, donor, volunteer, beneficiary, and service-user information it stores.

Compromised credentials were used to access Beacon and create copies of database backups belonging to charities using its customer relationship management platform.

The London-based provider said the available evidence indicates that the copied backups were probably downloaded, although it has not conclusively established exfiltration. Beacon discovered the incident on 29 July and notified customers on 3 August.

The company supports more than 1,000 charities. It has not disclosed how many customer databases were reached, whether the intruder could access every backup, or how the credentials were compromised.

Beacon engaged external cybersecurity specialists, introduced containment measures, and began working with law enforcement and regulators. It said the incident did not cause a material interruption to the service and customers continued to access the platform.

No ransom demand had been received when the company issued its guidance, and Beacon said it had not found the information circulating on the dark web. Those observations do not establish that the backups remained inside its environment, but they define what had been detected publicly at that point.

The potential impact varies substantially between customers because each charity decides which records and fields it stores. A database may contain donor and supporter details, gift histories, volunteer records, event participation, memberships, beneficiary contacts, case-management information, communications, and internal notes.

Some records may reveal relationships with politically, medically, or socially sensitive causes. Others can contain information about vulnerable people receiving support. The CRM label therefore does not describe a uniform or low-sensitivity dataset.

Beacon has told customers to assess whether they need to report the incident to the Information Commissioner’s Office. Under UK data protection law, notification depends on whether a breach is likely to create a risk to people’s rights and freedoms, while direct communication is required where a high risk is likely.

That decision rests primarily with each charity because it understands the information it entered and the context in which it was collected. Beacon processes the data through its platform, while its customers generally determine the purpose and content of their records.

The model places a large incident-response burden across organisations with widely differing resources. Each must establish what was present in its database, identify sensitive groups, document its assessment, and coordinate communications with trustees, staff, regulators, partners, and affected people.

Backups complicate that exercise because they represent the database at a particular time rather than only its current contents. Information later corrected, deleted, or restricted in the live system may remain in a retained backup.

Beacon advertises automatic daily backups retained for 30 days. Its investigation will need to establish which backup generations were available to the compromised identity, whether they were encrypted in a way that remained protective after download, and which customer environments were included.

The confirmed facts support unauthorised access and the creation of backup copies. Download is considered probable but not yet conclusively established, while the affected customer and record counts remain unknown.

×