Beacon Data Security Incident

On Monday the 3rd August we were informed by Beacon, external provider of Middle East Media’s supporter database system, of a data breach to their system.

This breach was directed at Beacon, one of the leading providers of charity databases, and not Middle East Media. Very sadly, this breach has impacted over 1,500 other charities using the same system.

Beacon believes copies of database backups were likely downloaded by an unauthorised third-party. It is therefore possible that personal information that Middle East Media stores in Beacon about you may have been taken. We are not currently aware of any misuse of the information that may have been taken.

What information could we hold?

The information might include some or all of the following:

  • Your full name
  • Email address
  • Postal address
  • Phone number
  • Records of your interactions with us
  • Your affiliation with us
  • Your donation history (no bank or card details are held in these records)

 

We want to assure you that Beacon immediately engaged external cyber-security experts to help them contain the incident and investigate it further. They are fully operational and have not experienced any suspicious activity since then.

Protecting your personal information is extremely important to us. As soon as we were informed, we followed our cyber security policy and process, reported the incident to the Information Commissioner’s Office (ICO) and followed the guidance shared by the ICO and Beacon. We assessed the potential risks with the information we have received and have taken every precaution, including emailing all of our supporters and publishing the information contained on this page.

We will continue to review our own processes and policies to ensure they are as robust as possible.

We are also in the process of reporting this to the Charity Commission.

Are my payments safe?

We do not store any credit or debit card details on Beacon so we are confident this will not be a factor to consider.

What should you do?

This sort of incident is sadly becoming common in modern life. Cyber criminals are increasingly sophisticated in their tactics.

We are incredibly saddened that the charity sector in particular has been targeted in this way. We can only hope that this does not hurt the trust of so many organisations working in very difficult times.

Here is what you can do to protect yourself always, not only in this particular case:

  • Be vigilant in the coming days and weeks about phishing emails, texts and phone calls that may seem to come from Middle East Media, or refer to your relationship with us. Cyber criminals can use the leaked information to make their scams more convincing.
  • Be cautious about unusual requests for money, banking information or security codes.
  • Consider updating the passwords of your email on a regular basis.
  • Do not open any suspicious links or attachments in emails.
  • If you receive any communications from us that seem suspicious, please contact us immediately through the contact details on our website.

 

We thank you for your understanding and patience and hope we can rely on your continued support.

If you have any concerns or wish to discuss this further then please contact our Data Protection Officer James Baldock at hello@mem.org and he or one of our team will reply.