We have recently been informed about a data security incident affecting Beacon CRM, a third-party software provider that Dove Cottage use to manage online donations and web enquiries.
What happened
Beacon has confirmed that an unauthorised third party gained access to their systems using compromised login credentials. Beacon's investigation, supported by external cyber-security specialists, has found evidence that copies of database backups were made and were likely downloaded by the unauthorised party.
What this means for your data
We are advising you of this potential breach due to our duty of care, not because we believe that you are particularly at risk. At this stage, there is no evidence that your personal information has been downloaded nor misused, but as a precaution, Beacon has advised us to assume that data held within our account may have been accessed. The information that we hold about our supporters may include:
Name
Contact details (email address and phone number)
Address
Record of donations or payments made to Dove Cottage (but no financial, card or bank details)
Information you have provided to us in connection with our services and activities, including Gift Aid declarations
It is important to note that we do not store sensitive financial information such as payment card details or bank account information within this system.
It is also important to make you aware that Dove Cottage are not alone in this incident – we are one of around 1500 charities and organisations that utilise the well-established database service provided by Beacon.
Beacon has confirmed that the affected service has now been secured, and there is no perceived risk to anyone currently using the platform.
What we have done
Since being notified, Dove Cottage has:
Informed our Board of Trustees and begun coordinating our response
Reported the incident to the Information Commissioner's Office (ICO), reference number IC-550339-L1Q2
Reported the incident to the Charity Commission for England & Wales
We are currently contacting our supporters directly to inform them of the breach and advise them to remain vigilant surrounding any unexpected communications.
What we are asking of you
If you have any concerns, or believe you may have been affected, please contact us at beacon@dovecottage.org. We will do our best to respond as quickly as possible.
We take the security of the data entrusted to us extremely seriously and are working hard to understand the full scope of this incident. We will update this page as we learn more.
Official statement from a Beacon spokesperson (for reference)
“We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.”
“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”