The Charity Commission has said it will publish guidance for organisations affected by a recent data breach at software firm Beacon CRM.
Beacon CRM, which supports more than 1,000 charities, earlier this week reported that “compromised credentials” were used to copy database backups with customer information.
A commission spokesperson confirmed it was in touch with Beacon CRM and the Information Commissioner’s Office (ICO) after several charities reported serious incidents.
“We are working to assist those with guidance and steps to enable them to address the data breach,” they said.
“This guidance will be published once we know the full extent of the issue.”
Following the cybersecurity incident, Beacon CRM urged its charity customers to consider reporting to the ICO.
In a statement to Civil Society today, the firm said that it was taking the matter “very seriously” and had notified all customers about the breach.
“Since containing the initial incident, we have not identified or observed any ongoing unauthorised access to Beacon’s systems,” a company spokesperson added.
Beacon CRM said that it immediately brought in external cybersecurity experts after learning about the problem and subsequently launched an investigation.
“Our focus is now on supporting them as much as possible in any onward communication of their own regarding potential data impact,” the spokesperson added.
An ICO spokesperson said that it has since received reports from impacted organisations and was assessing the information provided.
“Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms,” the spokesperson said.
"If an organisation has been impacted by this incident, they should use our self-assessment tool.”
Charities contact supporters
The Sheffield Hospitals Charity, Breast Cancer UK and research charity IVAR are among those which have contacted followers after the breach.
Other charities such as the Molly Rose Foundation, the Circle and the Air Cadets Charity have released statements to reassure supporters, donors and service users.
The Molly Rose Foundation said: “We understand that this will be worrying to those affected, and we are truly sorry that this has happened. Protecting your personal information is extremely important to us.
“We are continuing to work with Beacon to establish precisely what information may have been accessed and whether any specific individuals face a heightened risk as a result.”
