Beacon CRM Data Breach


Featured image

Saint Catherine’s Hospice has been informed of a cyber-security incident affecting Beacon CRM, the supplier that provides the system we use to manage donations and supporter information. 

On Monday 3rd August, Beacon advised us that an unauthorised third party had gained access to its systems. This was a wider incident affecting all organisations that use Beacon and was not targeted at Saint Catherine’s Hospice. You may have read about this incident in the national news.  

The personal data we hold on Beacon may include your postal addresses, email addresses, telephone numbers and details of donations made to the hospice, if this information has been shared with Saint Catherines.  

No payment-card details or bank account information is stored within Beacon, so these details were not involved in this incident. No usernames or passwords were involved in the incident.  

In response to the incident we have taken appropriate steps to protect our systems, including temporarily disconnecting Beacon from our other systems. Beacon have engaged an outside cyber security specialist to secure their systems. We are also in the process of reporting the incident to relevant authorities such as the Information Commissioners Office and the Charity Commission. 

Although Beacon have informed us that they are not currently aware of any misuse of our supporters’ information and there is no indication that the data has been posted online, we encourage everyone to remain vigilant for unexpected emails, telephone calls or text messages.  

Please be particularly cautious of unexpected requests for payment details, passwords, security codes or other sensitive personal information. Saint Catherine’s Hospice will never ask you to provide a password or security code and we have not changed any of our banking details.  

We understand that this news may be concerning. Protecting the information entrusted to us is a priority, and we take our data protection responsibilities extremely seriously. We will continue to work internally and with Beacon and will provide further updates if they will be helpful to you.  

You do not need to take any further action. 

Anyone with questions or concerns can contact us at: 

Email: beaconincident@saintcatherines.org.uk