Beacon CRM security incident
Last updated: Thursday 6 August, 11.30am
Important information about the Beacon CRM cyber security incident:
At PEEK – Possibilities for Each and Every Kid, protecting the personal information of our supporters, donors and partners is extremely important to us.
On Monday 3 August, we were informed by our customer relationship management (CRM) provider, Beacon CRM, of a cyber security incident involving unauthorised access to its systems. Beacon CRM is a third-party provider used by PEEK to manage information relating to our supporters, donors and business contacts.
This incident did not involve unauthorised access to PEEK’s own IT systems. It is limited to Beacon’s systems, and we are working closely with Beacon to understand the full extent of the incident and its potential impact.
Beacon has advised that, based on the information currently available, copies of database backups were accessed and are believed to have been downloaded by an unauthorised third party. Beacon is investigating the incident with the support of specialist cyber security experts and is working with the relevant authorities.
The information potentially affected relates only to members of the public who have donated to PEEK and business contacts whose contact details are generally already available in the public domain.
For individual donors, this may include names, postal addresses and email addresses. For business contacts, the information held relates to contact details that are generally already publicly available.
No information relating to the children, young people or families who access PEEK’s services is held within Beacon, and none of this data has been affected. Beacon does not store payment card or bank account details, and PEEK does not store financial information within Beacon.
As soon as we became aware of the incident, we began assessing the potential impact and notified the Information Commissioner’s Office (ICO). We are continuing to work closely with Beacon as its investigation progresses and will take any further action required.
At this stage, there is no evidence that any personal information has been misused. However, we encourage anyone who may be affected to remain vigilant for unexpected emails, telephone calls, text messages or other communications claiming to be from PEEK or Beacon. Please be cautious about clicking on links, opening attachments or sharing personal information unless you are confident the communication is genuine.
We understand that this news may be concerning and sincerely apologise for any worry it may cause. We take our responsibility to protect the information entrusted to us very seriously and remain committed to keeping our supporters and partners informed as more information becomes available.
If you have any questions or concerns, please contact info@peek.scot.