Important data security notice

We are sorry to inform you of a cyber security incident involving Beacon, the third-party Customer Relationship Management (CRM) system we use to securely manage donor and supporter contact information.

We understand that this news may be concerning, and we are treating the matter seriously.

Beacon has experienced unauthorised access to its systems. Based on the information currently available, it is possible that some personal information relating to our contacts was involved in this incident. This may include sensitive information such as name, date of birth, email address, postal address, phone number and whether someone is a service user.

Importantly, we have been advised that no financial or payment information was involved in this incident and that it does not affect our Patient Management System, which contains information relating to appointments and support provided by Big C.

We sincerely apologise for any worry or inconvenience caused. We know how important it is to protect your personal information and want to reassure you that we are treating this matter with the utmost seriousness. We are working closely with Beacon to understand the full circumstances of the incident and any potential impact.

Please see the below FAQs for further information, but do not hesitate to contact us on dataprotection@big-c.co.uk or 01603 619900 if you have any questions or concerns.

Q: What happened?

Beacon’s current understanding is that unauthorised access was gained through compromised credentials, and that copies of database backups may have been accessed and downloaded. Beacon’s investigation is ongoing, but at this stage there is no evidence that any data has been published, shared or misused.

Beacon became aware of a potential security breach and notified Big C and other affected charities of the incident. They immediately engaged external cyber security specialists to contain the incident and conduct a full investigation.

Q: What data was accessed?

Currently, Beacon’s investigation has confirmed that copies of their customer’s database backups were made and likely downloaded by the unauthorised third-party. Big C is one of their customers, as well as approximately 1,500 other charities.

This data may include sensitive information such as:

  • Name
  • Date of birth
  • Email address
  • Postal address
  • Phone number, and
  • Whether a contact is a service user.

Importantly, we have been advised that the incident does not involve any financial or payment information.

This does not affect our Patient Management System that relates to appointments and support details.

Q: Who is Beacon?

Beacon CRM is a third-party customer relationship management platform designed specifically for charities. For more information on Beacon please visit their website.

Q: What has Beacon done to secure their systems?

Having identified the probable root cause of this unauthorised access, Beacon have remediated the vulnerability and reset all credentials for services and accounts integrated with Amazon Web Services (AWS). To ensure the continued security of our systems they have deployed SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) across their environment and engineer endpoints. These security software solutions continuously scan their environment for Indicators of Compromise and suspicious activity. Alerts from these solutions are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Through this monitoring, their external cyber security experts have been able to confirm that, since containing the initial incident, they have not identified or observed any ongoing unauthorised access to Beacon’s AWS environment or engineer / developer endpoints. 

Q: What is Big C doing in response?

We are working with Beacon to understand the full details of the incident and what information may have been affected. We have sought assurance about the steps Beacon has taken to secure its systems and will continue to monitor the situation closely. 

We have reported the incident to the ICO.

Q: What is Big C’s advice following Beacon’s data breach?

As a precaution, we recommend you:

  • Remain vigilant and take extra care with any unexpected emails, text messages or phone calls
  • Be cautious of requests for personal information
  • Avoid clicking on links or opening attachments from unknown or unexpected sources
  • Are alert to any unexpected emails, calls or messages from someone claiming to be from Big C or acting on our behalf. If you are unsure whether a message is genuine, please contact us directly at dataprotection@big-c.co.uk or call 01603 619900 to verify it.

Let’s keep in touch

Subscribe to our mailing list to receive news and updates from Big C.