Christian charities in the UK affected by cyber attack

Computer laptop dark
 Unsplash / Andras Vas

A cyber-security attack has given hackers unauthorised access to the data of Christian organisations in the United Kingdom. 

Hackers infiltrated the systems of Beacon, a modern, cloud-based Customer Relationship Management platform for the charity and non-profit sector, based in Shoreditch, London, on July 29.   

“We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers,” a spokeswoman for Beacon told Christian Daily International. 

“We immediately engaged external cyber-security experts to help us contain the incident and investigate.”

The spokeswoman said the company understood the issue is “concerning” for customers and she promised “we’re taking it very seriously.” 

“We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact,” she said. 

“Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.” 

Embrace the Middle East is a UK-registered Christian charity based in High Wycombe, Buckinghamshire, that works with local Christian partners to provide healthcare, education, and humanitarian aid across the Middle East. 

The Christian charity issued a public statement on Aug. 5 in which it acknowledged an awareness of a data security incident. 

“We are aware of a data security incident recently reported by Beacon, the database provider we use to help manage supporter information and are working closely with them to understand whether there is any impact on Embrace supporter and partner information,” said Embrace the Middle East.

“We appreciate that news of a data security incident may be concerning for our supporters. Protecting the personal information shared with us is extremely important, and we are treating this matter with the utmost seriousness.”

Beacon's investigation is ongoing, according to the charity. 

“We are in regular contact with their team and working closely together to assess any potential impact,” the charity added. 

Embrace the Middle East said that at this stage, there is insufficient evidence to confirm that supporters or partner information have been affected. 

“We will continue to monitor the situation closely and review any new information as it becomes available,” the charity told supporters. “We would encourage you to be extra vigilant with your personal information at this time.

“If there is anything supporters or partners need to know or any action they need to take, we will communicate this clearly and promptly.”

The charity asked for prayer for all those impacted by this incident including Beacon and other charities. 

Keith Grafham, Chief Executive Officer of 24-7 Prayer International, also disclosed the international prayer charity had been affected. 

In a public statement to supporters, Grafham said a security incident involved Beacon, a service provider, which stores contact and supporter information on behalf of 24-7 Prayer International.

“Beacon has told us that a third party gained unauthorised access to its systems and made copies of the data they were managing,” said Grafham. “Based on the evidence currently available, they were likely downloaded. The system is now secured.”

Grafham explained to supporters that personal information was held in the affected system and may have been included in those copies.

This includes names, email addresses, but not payment or credit card details. Financial details are held in a separate secure system.

“We recognise that receiving this email may feel concerning and we are sorry that there is a possibility your personal information may have been affected,” added Grafham. 

“At present, neither 24-7 Prayer nor Beacon has evidence that your information has been published online or used fraudulently. However, misuse is possible, and while we will continue to assess the risk, we ask you to remain vigilant.

“The main risk is that someone could use your name, contact details or association with 24-7 Prayer to make a fraudulent email communication appear genuine. There is also a risk that you may be contacted, and that your association with 24-7 Prayer is no longer confidential.”

Beacon has taken steps to contain the incident, engaged external cyber-security specialists and begun a forensic investigation, according to Grafham. 

Grafham suggested precautions such as caution about unexpected communications referring to 24-7 Prayer or Beacon, not providing passwords or banking information to unexpected emails, text messages or callers. 

“Neither 24-7 Prayer nor Beacon will ask you for this information,” said Grafham. 

“Do not click links or open attachments in an unexpected message. Contact 24-7 Prayer through contact details you already know to be genuine.

“Tell us immediately if you receive a suspicious communication that appears to use information connected with 24-7 Prayer.”

Graham said the charity is taking the incident “very seriously” and reported the issue to both the UK Information Commissioner’s Office and the Charity Commission.

“We have worked with Beacon to confirm that they have blocked the unauthorised access and prevented any further exposure,” he said. “They have also implemented additional security measures.”

About 28% to 30% of U.K. charities - representing roughly 57,000 to 61,000 organizations - reported experiencing a cybersecurity breach or attack in recent years, according to the British government's Cyber Security Breaches Survey.

Most Recent