‘Huge human error’ caused ‘biggest ever’ cyber attack on charity sector with millions warned their data may have been stolen


A ‘huge human error’ triggered what could be the biggest ever cyber-attack on the UK charity sector.

Up to 1,000 charities have been caught up in the hack, including Breast Cancer UK, National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation.

Cyber criminals targeted Beacon CRM, which provides customer management software to the charity sector.

It is thought the company mistakenly published an access key online that allowed hackers to copy its databases.

The blunder means millions of charity supporters may have had their names and contact details stolen in what experts described as a colossal ‘cock-up’.

Jake Moore, of cyber security firm ESET, said it was ‘a huge human error’.

Beacon said it disagreed with this interpretation. 

Payment information has not been compromised. But security experts warned that hackers would use stolen details to launch sophisticated phishing attacks, armed with details of which charities victims have donated to.

Up to 1,000 charities have been caught up in the hack, including Breast Cancer UK, National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation

Up to 1,000 charities have been caught up in the hack, including Breast Cancer UK, National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation 

Victims have been advised to change their passwords and be vigilant for scam emails or texts that could contain malicious links. 

There are fears the elderly could be particularly vulnerable as they are often generous donors.

Beacon has 1,000 clients in the charity sector, including Girlguiding, Kidney Care UK, the British Deaf Association, various NHS and animal rescue charities, and Blesma, an organisation that supports amputee veterans.

It is not yet known how many were affected by the data breach.

But Beacon has advised all its customers to assume that they may have been hacked.

Historic Buildings and Palaces, formerly the Ancient Monuments Society, told members that the stolen data may include ‘your name, contact details, communication preferences, membership or donation history, Gift Aid records, event bookings, correspondence or notes relating to your relationship with us, and, for some individuals, gender and date of birth information’.

English National Ballet and the Molly Rose Foundation, an online safety charity, have also issued statements warning that names, addresses, contact details and donor records may have been stolen.

In an update, Beacon said it suspects it was hacked after an Amazon Web Services (AWS) access key was ‘potentially exposed’ online.

AWS provides data and cloud services to millions of customers worldwide.

Alan Woodward, professor of cyber-security at Surrey University, said it appeared as though Beacon had published the key inadvertently as part of the code for its website.

‘It should not have happened,’ he said. ‘It’s a cock-up, to use a technical term.’

He added: ‘Normally, before that kind of code is published, there are automated tools that do security sweeps to make sure that sort of thing doesn’t happen. But in this case, that clearly wasn’t done.’

Professor Woodward said the attack was significant because it hit one organisation ‘covering many charities at once’, creating a ‘force multiplier’ effect.

‘I’m not aware of anything that has hit [the sector] as hard as this,’ he added. ‘It could be bigger than anything that has gone before.’

Kevin Curran, professor of cyber security at Ulster University, said: ‘A lot of criminal organizations are increasingly targeting the IT manager because they know that they have the keys to the kingdom.’

He warned a ‘significant percentage’ of the stolen data ‘will belong to elderly people’ who are known to be ‘generous with charity’.

Kevin Curran, professor of cyber security at Ulster University, warned a 'significant percentage' of the stolen data 'will belong to elderly people'

Kevin Curran, professor of cyber security at Ulster University, warned a ‘significant percentage’ of the stolen data ‘will belong to elderly people’

The Met’s Cyber Crime Unit and the Information Commissioner’s Office (ICO) are investigating the breach, which occurred between July 27 and July 31.

Beacon, which is based in London, was set up in 2017 to help charities with their databases.

It carries cyber-security certifications on its website, including a government-backed credential.

A spokesman said: ‘We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged the support of external cyber-security experts who swiftly contained the incident.

‘Data security is something we take incredibly seriously, and we recognise the impact this incident has had on our customers. We remain committed to supporting them as much as possible in any onward communication of their own regarding potential data impact.’



Source link

Man United summer target Ederson breaks silence over failed move to Old Trafford – revealing he passed medical so ‘doesn’t know what happened’

Matthew Rhys Reveals Widow’s Bay, Keri Russell’s Diplomat Crossover Idea

Leave a Reply

Your email address will not be published. Required fields are marked *