Q: What exactly happened?
A: We recently experienced a cyber-security incident in which an unauthorised third party gained access to our systems. We acted quickly to identify the threat and contain it, and Beacon is operating normally.
Q: How did this happen?
A: We are currently investigating the full circumstances of the incident with external cyber-security specialists, but our current understanding is that compromised credentials were used to gain access to Beacon.
Q: What data was accessed?
A: Our investigation into the scope of data that may have been accessed is ongoing. At this stage, we understand copies of database backups were made. Whilst the exfiltration (copying or taking) of that data hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded. Given the nature of data, including personal data, you hold in our system, we wanted to let you know early on. We have created a Security Incident Response Guide page to support you with next steps including understanding what and how you might need to inform your own contacts. Please visit that page at www.beaconcrm.org/incident-guidance.
Q: Was the data downloaded encrypted?
A: We wanted to inform you of this incident as soon as possible, but please understand that means we don’t have all the answers yet. We store data in an encrypted state, but it is possible that the unauthorised third party responsible for this incident was able to decrypt it. Out of an abundance of caution, you may want to assume this is the case.
Q: Does this affect my account or the data I have shared with Beacon?
A: We are investigating the scope of the incident carefully. Because we understand copies of database backups were made, we are notifying customers so you can review the data potentially impacted and consider whether you need to notify your contacts. We have provided some step-by-step guides directly to customers on how to do this and shared template communications for your use, should you need to notify your contacts.
Q: Is Beacon still operational?
A: Yes, Beacon is fully operational and working as normal. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident.
Q: Are my payments safe?
A: There is no evidence that any card details have been compromised, and you can safely continue to collect payments via Beacon forms, but you must follow the steps in the Security Incident Response Guide in order to update your payment providers and apps.
Q: When will you have more information?
A: We are progressing our investigation as quickly as we can with the help of cyber-security specialists. Cyber-security investigations are complex and can take time. We will update the Security Incident Response Guide webpage as soon as we have any relevant information to share. Please keep an eye on our website for updates and visit our guide for immediate step-by-step support.
Q: Will I be told if our customer data was accessed?
A: Because we understand copies of our back-up systems were likely downloaded, any data you were storing in your Beacon account might have been downloaded. For that reason, we recommend that you progress with your analysis at this time to determine whether you need to notify any of your contacts. Please make use of our Security Incident Response Guide (www.beaconcrm.org/incident-guidance) to support you.
Q: What else should I do in the meantime?
A: Firstly, as a precaution, we are prompting password resets for all users and we recommend you make it long and unique.
Secondly, because we understand copies of our back-up systems were likely downloaded, any customer data you were storing on your Beacon account might have been downloaded. For that reason, we recommend that you progress with your analysis at this time to determine whether you need to notify any of your contacts. Please do make use of our Security Incident Response Guide (www.beaconcrm.org/incident-guidance) to support you.
Q: How can I be confident that Beacon takes security seriously?
A: Keeping your data secure is the most important thing we do at Beacon and we have significant measures in place to protect your data. We brought in expert third-party specialists as soon as we discovered this incident, and we are continuing to work with them to understand what happened and ensure it does not happen again. We are also reporting the incident to the relevant authorities and regulators.
Q: Will this happen again?
A: Please know that we are taking this incident very seriously. Working with our expert third-party specialists, we are conducting a comprehensive investigation to understand what happened and to ensure we implement any additional safeguards needed to prevent this from happening again. Security is a continual process for us, and we are committed to keeping your data safe.
Q: I have a question that is not answered here. Who should I contact?
A: Please read our dedicated Security Incident Response Guide web pages at www.beaconcrm.org/incident-guidance, which have step-by-step guides, FAQs and template documents. If you have further questions that can’t be answered using the webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at incident@beaconcrm.org. Our team will be here to help. We will come back to you as soon as possible, but please bear with us as volume may mean we are slower to respond in the short term.
Q: I am concerned about the security of my data and have questions that you haven’t addressed. What should I do?
A: Please contact our support team and let us know your concerns. We are here to help and will be happy to discuss this with you.