Back Artsprofessional Breaking: Scores of cultural organisations affected by possible data breach after cyber attack
A data platform used by numerous organisations in the arts and culture sector has been hit by a cyber attack, placing some of the information stored in it at risk. Beacon CRM, which provides customer services management systems has said it is conducting a “thorough forensic investigation” with specialists after it became aware that compromised credentials were used to gain access.
In a statement updated at 10am today (4 August) , Beacon CRM said its current understanding is that copies of its database backups were made by those infiltrating the system, adding: “Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded.”
Beacon has published a response guide for charities using its platform, many of which are cultural organisations, advising them to check their regulations for how to proceed.
The CRM software provider became aware of a potential cyber attack on 29 July, after which it said it “immediately” engaged external cyber-security experts to help investigate and secure their systems.
Chiswick House and Gardens Trust released a statement, saying it uses Beacon to manage information supporters, donors and fundraising contacts.
It is contacting those it believes may have been affected so they “can take sensible precautions”.
The information potentially accessed includes names, details, donation dates and amounts and any correspondence on personal records.
It continued: “There is currently no evidence that your information has been published or misused, and we are not aware of any fraud or harm resulting from this incident.
“However, the information could potentially be used to make phishing emails, telephone calls or fraudulent requests appear more convincing. It could also lead to unwanted disclosure of your details, charitable giving or relationship with Chiswick House and Gardens Trust.”
The trust has reported the incident to the Information Commissioner’s Office and to the Charity Commission.
In an email today, English National Ballet also said some business’ information “may have been included in the affected data” from the cyber attack.
It warned contacts and organisations it works with to remain vigilant, as the attack happened while ENB was transferring its data to Beacon from its provider.
The details that may have been affected include email addresses, business phone numbers and business addresses.
ENB said the data accessed does not include passwords or payment information.
“While no passwords or payment details were exposed, we recommend remaining cautious of any unexpected emails and always verifying the sender before clicking on links,” the ENB email warned.
“There has been no disruption to our website and you can continue to use our online services.
“We are so sorry to be sharing this news. We know this will be concerning, and we’re taking it seriously.”
A Beacon spokesperson told Arts Professional: “We recently experienced a cyber-security incident that involved temporary unauthorised access to Beacon’s systems. We immediately took steps to contain the incident and engaged external cyber-security experts to help us investigate.
“Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.
“We’ve informed all of our customers this incident as well as the relevant regulators.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
