Data Breach Incident FAQs

Please click the 'X' to view answers to these frequently asked questions.

 

What happened?

We are very sorry to have to inform you about a recent incident regarding  the data we store. Beacon CRM, our database provider, has experienced a cyber breach, due to compromised credentials being used to gain unauthorised access to its system. This has unfortunately led to copies of the backups being made and ‘likely’ downloaded. They have informed us that they are very unlikely to be able to narrow down exactly what data was downloaded and which organisations were affected, so Beacon are advising us 'out of an abundance of caution' to treat our data as compromised.

 
MoreClose

What does this mean for me?

Any information you have shared with us, will have been stored in Beacon and therefore could have been accessed. Information like your name, contact details, giving history, events or trips you have been on, could have been accessed.

It is highly likely that that this breach was NOT targeted at our organisation or others like us, but the whole of Beacon’s customer base (over 1,000 charities ranging from your youth sport to pet rehoming charities and much more), and we remain hopeful that there was no malicious intent towards our work. It is possible however that any information accessed could be used in phishing scams.  

We are reassured that there is currently no evidence that any of the information has been shared or misused. Beacon has said …  

“(We are) conducting continued online monitoring of the dark web, as is standard practice in these kinds of incidents. So far, we haven’t seen any reference or data linked to this incident.”  

Very importantly, we do not store any financial information (bank card or account details) in Beacon, so nothing of that nature will have been accessed.

MoreClose

What has Pioneers done in response?

As soon as we were informed of the incident, we took all the necessary precautions to ensure all our systems and information are secure.

We sought advice from the ICO (Information Commissioner’s Office) and have reported the incident to them and submitted a Serious Incident Report with the Charity Commission.

We have assessed the risk to those we hold information on and shared the situation with them.

We are continuing to work closely with Beacon as we seek to understand what happened and what data could have been accessed.

MoreClose

What do I need to do?

Please be alert to any suspicious emails, phone calls, or text messages, including those which appear to have a connection to, are from, or reference us or Beacon. Criminals may use personal information to make fraudulent messages appear convincing.
 

  • Do not open suspicious links or attachments.
  • Be cautious of any unexpected requests for money, codes, banking information, or passwords.
  • If you’re not sure, check with us by calling the office or using our official email address on the website.
  • Please inform us as soon as possible if you receive anything suspicious that appears to be from, or relate to, us.
MoreClose

How can I get support?

We are very sorry indeed for the inconvenience and concern this incident raises. Please be assured we are working very hard to ensure all our systems and information are secure. We continue to work with Beacon to understand what happened and support one another through this. Please reach out to us if you have any questions or concerns.

You can also find some helpful advice at the National Cyber Security Centre: https://www.ncsc.gov.uk/guidance/data-breaches