.wp-block-jetpack-rating-star span:not([aria-hidden="true"]) { display: none; }/* Inline styles */ .amp-wp-inline-b1c50de8a8e3192d838b8a622042f321{max-width:310px;}

Cybersecurity Breach Exposes Donor Data Christian Ministries among nonprofits hit by data breach at Beacon CRM

Share

A cybersecurity breach at Beacon CRM has exposed the personal data of supporters at more than 1,000 nonprofits, including several prominent Christian ministries.

Photo by Allison Saeng / Unsplash+

Christians in Sport, Keswick Ministries, Kintsugi Hope, Langham Arts, Living Out, Operation Mobilization (OM) and ReSource have all notified their supporters and donors about the breach, Premier Christian News confirmed.

Beacon CRM, based in the United Kingdom, provides software that many U.K. nonprofits use to store supporter data and communicate with donors. The company said it detected unauthorized access to its systems and that supporter data was likely downloaded by a third party July 29. Beacon notified its customers Aug. 3.

The leaked data may include names, phone numbers, email addresses and residential addresses, the company said. No payment details were compromised, Beacon said, adding that it is unlikely to determine precisely what other data the hacker accessed.

Affected organizations have urged supporters to be alert for suspicious messages — particularly those requesting personal or payment information, claiming changes to payment or account details, or containing unfamiliar links or attachments.

Operation Mobilization UK, in a message to supporters, wrote: “Based on the information currently available, we have no evidence that credit card, bank account information and any other financial details have been misused. … We also recognise that many Christian and non-Christian charities and their supporters have been affected too. We invite you to pray for wisdom and for the safety of everyone involved.”

Access to MinistryWatch content is free. However, we hope you will support our work with your prayers and financial gifts. To make a donation, click here.

OM said it is taking steps to protect supporters’ information and has notified the U.K.’s Information Commissioner’s Office.

The breach occurred despite what Beacon describes as “ironclad security features,” including private cloud hosting, real-time monitoring and ISO 27001:2022 certification — “the most highly regarded global standard for data security.” Fundraising Magazine has ranked Beacon the No. 1 CRM software provider for seven consecutive years and gave it a 4.7 out of 5 rating in its security index, well above competitors.

A spokesperson for Beacon CRM said, “We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact.”

Sheffield Hospitals Charity, a secular nonprofit, was also affected. Chief Executive Beth Crackles told supporters in an email: “At this stage, there is no evidence that supporter information has been published or misused, and we are not aware of any fraud or harm resulting from this incident.”

Beacon CRM said it has hired outside experts to investigate and mitigate the breach. Customers can continue to access the system as normal.

TO OUR READERS: The mission of MinistryWatch is to help Christian donors become more faithful stewards of the resources God has entrusted to them. Do you know of a story that will help us fulfill our mission, or do you want to give us feedback about this or any other story? If so, please email us at info@ministrywatch.com.