Gambling with Lives has disclosed it has been impacted by a cybersecurity breach at one of the charity’s third-party information platform providers.
On 3 August, Beacon, the platform via which Gambling with Lives manages information related to a range of stakeholders and external groups, reported its systems had been accessed by an unauthorised person or persons.
Beacon told Gambling with Lives that compromised credentials were used to access the system and “copies of back up files were likely downloaded by the unauthorised third party”.
Beacon confirmed it has engaged cybersecurity experts, informed the Information Commissioner’s Office (ICO), secured the system and is investigating the incident.
Gambling with Lives uses the Beacon system to manage information related to its beneficiaries, donors, funders and supporters.
Beacon is also used by the charity to manage its mailing list and newsletter subscribers, community fundraisers, political stakeholders and suppliers.
Gambling with Lives said information stored with Beacon “may include some or all” of the following:
- Name, address, contact details (email and phone number)
- Date of birth
- Records of donations made to Gambling with Lives (note: any financial information such as bank account details are not stored in Beacon)
- Records of interactions or engagements with Gambling with Lives
- Information provided to Gambling with Lives in connection with its services and activities such as health information and safeguarding information
A Gambling with Lives statement read: “We are continuing to work with Beacon to establish precisely what information may have been accessed and whether any specific individuals face a heightened risk as a result.”
Gambling with Lives also noted it had informed the Charity Commission regarding the incident.
Beacon confirmed the breach publicly on Tuesday, 4 August. Gambling with Lives made its own public statement on Thursday, 6 August.
The charity added it wasn’t “currently aware of any misuse” of personal information as a result of the incident.
Other charities, including the Sheffield Hospitals Charity and suicide prevention organisation the Molly Rose Foundation, have announced they were impacted by the breach.
The English National Ballet also revealed it had been caught up by the Beacon systems compromise.
A statement from Gambling with Lives chair of trustees Charles Ritchie read: “We are grateful for your trust in Gambling with Lives and our ongoing work together.
“We appreciate this news may be concerning and we sincerely apologise for any worry or inconvenience this incident may cause.
“If our investigation identifies any further information that may affect you, we will provide an update as soon as possible.”
A Beacon spokesperson said: “We recently experienced a cybersecurity incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers.
“We immediately engaged external cybersecurity experts to help us contain the incident and investigate.
“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact.
“Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”
The post Gambling with Lives impacted by cybersecurity breach at third-party supplier first appeared on EGR Intel.
Compromise involving CRM provider Beacon sparks concern across charity sector, as Gambling with Lives warns records of donations could have been downloaded and stolen
The post Gambling with Lives impacted by cybersecurity breach at third-party supplier first appeared on EGR Intel.