Jewish charities among those potentially affected by major cyber attack

Beacon CRM, which provides software to more than 1,500 UK charities - including Masorti UK, JTeen and Friends of the Sick (Chevrat Bikkur Cholim), experienced a major breach last week

A number of Jewish organisations are among those which may have been affected by a major cybersecurity attack on a UK company providing CRM (customer relationship management) services for charities.

Beacon CRM, which provides a software system for charities which is often used to record data, including that of members and donors, confirmed last week that “copies of database backups were made and likely downloaded” by an “unauthorised third-party”.

It went on to say that “it is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded.”

Since then, Jewish charities such as Masorti UK, JTeen and Friends of the Sick (Chevrat Bikkur Cholim) have issued public statements confirming that they were Beacon CRM customers, and warning those who may have interacted with them to exercise extra caution.

Masorti contacted its members, telling them that “As you may already be aware, Beacon, a third-party CRM client used by Masorti Judaism to interact with members and supporters, experienced a cyberattack last week. Beacon, which is used by over 1500 charities, yesterday verified that ‘a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor’.

“This most likely includes data held about individuals who have interacted with Masorti Judaism such as name, postal address, email, phone number, records of donations and payments since 2018, and, in a minority of cases, date of birth.”

The denomination went on to say that “In line with what hundreds of other similarly affected charities are doing, we are writing to let you know about the incident and to urge caution when dealing with communications which you might suspect are malicious or seem unusual. There is no evidence to suggest that the stolen information has yet been misused but there remains a possibility that it might be.

“We want to reassure you in the strongest terms that data held by Beacon does not contain any financial details, credit card numbers, or bank account information. Furthermore, no private religious, personal, or confidential pastoral records are stored within this system.”

Masorti also said that “Beacon have pledged to do a full investigation, and if we receive notice that our data was included, we will confirm that with you. For the time being, there is little to do other than the typical essentials of digital hygiene: be careful of phishing attempts via scam and spam phone calls, emails, texts, and always verify the sender before clicking on links in emails.”

JTeen and Friends of the Sick (Chevrat Bikkur Cholim) issued similar messages to. The charities have all reported the situation to relevant authorities, as have many of the other organisations affected.

The Charity Commission issued a statement on the subject of the breach, saying: “A number of affected charities have submitted serious incident reports to the Commission and we encourage trustees to continue to follow our guidance on serious incident reporting. This requires you to report incidents which results in or risks significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation.

“In the meantime, we would encourage trustees to consult the Commission’s guidance for charities on dealing with cyber crime and the ICO’s guidance for organisations.

“Trustees should consider their reporting obligations to other regulators, notably the ICO, and to individuals whose data is stored on Beacon systems on behalf of your charity.

“We know many Beacon customers have moved promptly to inform their supporters about this incident. Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work.

“We appreciate the additional resources charities will need to devote to addressing this issue and the Commission will seek to ensure its own regulatory engagement with affected charities is proportionate, while seeking to ensure trustees are fulfilling their responsibilities.”

read more: