Beacon recently experienced a cyber-security incident that affected our systems. We want to keep you informed about what happened, what we are doing about it, and what this means for you.
We will be updating this page with relevant new information as our investigation progresses.
All,
We recognise it has been a frustrating time for our customers as we sought to get further detail on what happened and we apologise that a lot of your questions have gone unanswered. This is because we just didn’t have the information to give to you - indeed, we might never know some of the answers we seek.
We did not want to speculate before the findings had been sufficiently verified, but we recognise that the limited information available until now has been frustrating.
We greatly appreciate all the patience you have shown us so far. We know this can’t have been easy.
Having worked as quickly as possible with our external experts on this incident, we want to share a further update with you all.
As before, Please visit our updated FAQs page (www.beaconcrm.org/incident-faqs) for immediate questions you may have.
If you have further questions that can’t be answered using these webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at incident@beaconcrm.org. We will come back to you as soon as possible, but please bear with us as volume may mean slower responding times in the short term.
Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party. We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems. It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded.
Whilst we store data in an encrypted state, our experts have advised us that based on the available evidence it is possible that the unauthorised third party responsible for this incident would have been able to decrypt it before copying it from our systems.
Having identified the probable root cause of this unauthorised access, we have remediated the vulnerability and reset all credentials for services and accounts integrated with Amazon Web Services (AWS). To ensure the continued security of our systems we have deployed SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) across our environment and engineer endpoints. These security software solutions continuously scan our environment for Indicators of Compromise and suspicious activity. Alerts from these solutions are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Through this monitoring, our external cyber security experts have been able to confirm that, since containing the initial incident, they have not identified or observed any ongoing unauthorised access to Beacon's AWS environment or engineer endpoints.
We have made a report to the ICO. Our case number is IC/0238/2026. We have also contacted the authorities via Report Fraud. Based on the information available, you should make an assessment of your own reporting obligations.
We understand that there has been some media interest in this incident. We wanted to share with you the statement we will be issuing to journalists that enquire directly with Beacon. We will not be commenting on the incident in any further detail. If you need to align on media approach or have questions from journalists you wish to ask us about, please contact press@beaconcrm.org and we’d be happy to help.
A Beacon spokesperson said:
“We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.
“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”
David Simpson
Chief Technology Officer
Beacon
Late last week, we discovered that an unauthorised third party had gained access to our systems. We immediately took action to contain this and brought in expert cyber-security support.
We’re treating this seriously. We’ve implemented immediate measures, including:
- Conducting a thorough forensic investigation with our external cyber-security specialists to understand exactly what’s happened;
- Working with law enforcement and relevant regulators as required;
- Conducting continued online monitoring of the dark web, as is standard practice in these kinds of incidents. So far, we haven’t seen any reference or data linked to this incident.
Our current understanding is that compromised credentials were used to gain access to Beacon, and copies of database backups were made. Whilst the exfiltration (copying or taking) of that data hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded.
You have placed your trust in us as your partner, and that responsibility matters to us. We are committed to supporting you through this as best we can.
As our investigation progresses, we will update you with what we’ve learned.
If you were storing data about people in your Beacon account, it is likely to have been downloaded and as such you need to evaluate whether you must in turn notify the people you store in Beacon. Please visit our Security Incident Response Guide (www.beaconcrm.org/incident-guidance) for our step-by-step guidance on what to do next.
Please visit our FAQs page (www.beaconcrm.org/incident-faqs) for immediate questions you may have.
If you have further questions that can’t be answered using these webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at incident@beaconcrm.org. We will come back to you as soon as possible, but please bear with us as volume may mean slower responding times in the short term.
Thank you for your patience and understanding.
David Simpson
Chief Technology Officer
Beacon