Victim Support has been informed of a cyber security incident affecting Beacon CRM, the supplier that provides the system we use to manage donations and supporter information.
Beacon’s investigation is ongoing, but the evidence currently suggests that copies of database back-ups were made and likely downloaded by an unauthorised third party.
As a result, some supporter information managed through this system may have been affected. This may include names, addresses, contact details and donation records.
Importantly, this system does not hold case records or details of support provided to victims, survivors or witnesses of crime, nor does it contain payment card details or bank account information.
We have taken immediate steps to protect our systems and have reported the incident to the Information Commissioner’s Office and the Charity Commission. We will also contact all those directly affected.
There is no action supporters need to take at this time. However, we encourage everyone to remain vigilant for unexpected emails, phone calls, messages or communications claiming to be from Victim Support or from Beacon.
We will never contact you unexpectedly to ask for payment details, passwords or other sensitive personal information.
We understand that this news may be concerning. Protecting the information entrusted to us is a priority, and we take our data security responsibilities extremely seriously.
We are continuing to work closely with Beacon to understand the full impact of this incident and to ensure appropriate measures are in place to protect the information held within its systems.
If you have any questions or concerns, please contact us via beaconincident@victimsupport.org.uk.
