On Monday 3rd August, we were notified by Beacon, our CRM software provider, that they had experienced a cyber-security incident.
Beacon immediately engaged external cyber-security experts to investigate the incident and secure their systems. Their investigation has now confirmed that an unauthorised third party gained access to Beacon’s systems and that copies of database backups were made and are likely to have been downloaded.
At this stage, Beacon has said that it is highly unlikely they will be able to establish exactly which data was downloaded or who it relates to. As a precaution, we therefore have to assume that all data stored in Beacon, including attachment files, may have been downloaded.
For our members, this may include information such as your contact details, address and other information you have provided to CMV Action. We store this information so that we can provide appropriate support and connect you with relevant groups and opportunities.
Beacon has also advised that, although data is stored in an encrypted state, based on the available evidence it is possible that the unauthorised third party was able to decrypt the data before copying it.
To the best of our knowledge, no financial information has been compromised. No financial information has ever been stored on Beacon. Beacon is a very well established software platform and was chosen in good faith by the charity following a rigorous process and utilising an external expert. It is regularly regarded within the sector as one of the best CRM platforms and has layered security defences and compliance structures, the details of which can be found here: Beacon | Trust and Data Security
What Beacon has done
Beacon has identified the likely cause of the incident and has taken steps to address the vulnerability. They have also reset all credentials for services and accounts connected to their Amazon Web Services (AWS) environment.
Beacon has introduced additional security measures, including systems that continuously monitor their environment and engineer devices for suspicious activity. These systems are monitored 24 hours a day, 7 days a week.
Beacon’s external cyber-security experts have confirmed that, since the initial incident was contained, they have not identified or observed any ongoing unauthorised access to Beacon’s systems.
Beacon remains operational and customers continue to access the platform as normal.
A Beacon spokesperson said:
“We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.”
“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”
Reporting the incident
Beacon has reported the incident to the Information Commissioner’s Office (ICO) under case number IC/0238/2026 and has also contacted the authorities through Report Fraud.
We are continuing to work closely with Beacon to understand the incident, its impact and the steps being taken to prevent something similar happening again.
Beacon is a well-established CRM platform and was chosen by CMV Action in good faith following a rigorous selection process and with the support of external expertise. We take the security of personal information extremely seriously and are reviewing the information provided by Beacon carefully.
What you can do
Please be cautious of unexpected emails, phone calls or messages claiming to be from CMV Action, Beacon or another organisation and asking you to provide personal information, passwords or payment details. Do not click on unexpected links or attachments
The fact that your information may have been downloaded does not mean that it will necessarily be misused. However, we want to be open about the situation and make sure you have the information you need to take sensible precautions.
We will continue to share further updates from Beacon as more information becomes available.
If you have any specific questions in the meantime please do not hesitate to get in touch: info@cmvaction.org.uk