Human Error Blamed for Largest-Ever Cyberattack on Charity Sector - Internewscast Journal
Human Error Blamed for Largest-Ever Cyberattack on Charity Sector

A suspected “major human mistake” is believed to have set off what may become the largest cyber-attack ever to hit the UK charity sector.

As many as 1,000 charitable organisations are understood to have been affected by the data breach, with names including Breast Cancer UK, the National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation among those caught up in the incident.

The cyber-attack was aimed at Beacon CRM, a technology company that supplies customer relationship management software widely used by charities to manage supporter information.

According to early assessments, the breach may have stemmed from Beacon accidentally making an access key publicly available online, potentially giving hackers the ability to duplicate company databases.

The apparent security lapse could mean millions of charity donors and supporters have had personal details, including names and contact information, exposed in what cyber experts have described as an extraordinary “cock-up”.

Up to 1,000 charities have been caught up in the hack, including Breast Cancer UK, National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation

As many as 1,000 charities are believed to have been affected by the hack, including Breast Cancer UK, the National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation

Jake Moore, a cyber security specialist at ESET, called the incident “a huge human error”.

Beacon, however, said it did not accept that characterisation of what happened.

Payment information has not been compromised. But security experts warned that hackers would use stolen details to launch sophisticated phishing attacks, armed with details of which charities victims have donated to.

Victims have been advised to change their passwords and be vigilant for scam emails or texts that could contain malicious links. 

There are fears the elderly could be particularly vulnerable as they are often generous donors.

Beacon has 1,000 clients in the charity sector, including Girlguiding, Kidney Care UK, the British Deaf Association, various NHS and animal rescue charities, and Blesma, an organisation that supports amputee veterans.

It is not yet known how many were affected by the data breach.

But Beacon has advised all its customers to assume that they may have been hacked.

Historic Buildings and Places, formerly the Ancient Monuments Society, told members that the stolen data may include ‘your name, contact details, communication preferences, membership or donation history, Gift Aid records, event bookings, correspondence or notes relating to your relationship with us, and, for some individuals, gender and date of birth information’.

English National Ballet and the Molly Russell Foundation, an online safety charity, have also issued statements warning that names, addresses, contact details and donor records may have been stolen.

In an update, Beacon said it suspects it was hacked after an Amazon Web Services (AWS) access key was ‘potentially exposed’ online.

AWS provides data and cloud services to millions of customers worldwide.

Alan Woodward, professor of cyber-security at Surrey University, said it appeared as though Beacon had published the key inadvertently as part of the code for its website.

‘It should not have happened,’ he said. ‘It’s a cock-up, to use a technical term.’

He added: ‘Normally, before that kind of code is published, there are automated tools that do security sweeps to make sure that sort of thing doesn’t happen. But in this case, that clearly wasn’t done.’

Professor Woodward said the attack was significant because it hit one organisation ‘covering many charities at once’, creating a ‘force multiplier’ effect.

‘I’m not aware of anything that has hit [the sector] as hard as this,’ he added. ‘It could be bigger than anything that has gone before.’

Kevin Curran, professor of cyber security at Ulster University, said: ‘A lot of criminal organizations are increasingly targeting the IT manager because they know that they have the keys to the kingdom.’

He warned a ‘significant percentage’ of the stolen data ‘will belong to elderly people’ who are known to be ‘generous with charity’.

Kevin Curran, professor of cyber security at Ulster University, warned a 'significant percentage' of the stolen data 'will belong to elderly people'

Kevin Curran, professor of cyber security at Ulster University, warned a ‘significant percentage’ of the stolen data ‘will belong to elderly people’

The Met’s Cyber Crime Unit and the Information Commissioner’s Office (ICO) are investigating the breach, which occurred between July 27 and July 31.

Beacon, which is based in London, was set up in 2017 to help charities with their databases.

It carries cyber-security certifications on its website, including a government-backed credential.

A spokesman said: ‘We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged the support of external cyber-security experts who swiftly contained the incident.

‘Data security is something we take incredibly seriously, and we recognise the impact this incident has had on our customers. We remain committed to supporting them as much as possible in any onward communication of their own regarding potential data impact.’

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Justin Timberlake and Jessica Biel Put On United Front in New Photo

Justin Timberlake shared a rare family moment on Tuesday, posting a photo…

Outstanding Refugee Award Winner Charged in Alleged Fraud Scheme

A Somali-born entrepreneur who once received Minnesota’s “Outstanding Refugee Award for Entrepreneurship”…

Nick Kyrgios Apologises After Positive Cocaine Test

Nick Kyrgios has announced that he tested positive for cocaine in a…

Texas Dad Accused of Killing Wife After Police Find Key Clue

A Texas man accused in the violent death of his estranged wife…

NYC Teaching Assistants to Receive $10K Pay Raise as Bill Becomes Law Without Zohran Mamdani’s Signature

A measure that would raise pay for New York City teaching assistants…

Diane Keaton’s Former Los Angeles Mansion Sells for Millions Under Asking Price

Diane Keaton’s former Los Angeles home in Sullivan Canyon has sold for…

Teen Lifeguard Suffers Spinal Injury in San Diego Drill

A young San Diego lifeguard is facing a long and difficult recovery…

Canadian Town Officially Grants Legal Rights to Trees

A small Quebec community has made Canadian history by formally recognizing trees…

Anthony Albanese’s International Travel Bill Reaches $4 Million for Taxpayers

Anthony Albanese’s taxpayer-funded travel bill topped $4million last financial year, with new…

Why Couple’s Kids Were on Fatal Boat Trip With Grandfather

Two young siblings killed in a New Jersey boating crash had reportedly…

Midwest Construction Worker Dies After Becoming Trapped in Storm Drain

An Ohio construction worker died while working inside a storm drain after…

Lindsay Clancy’s Psych Ward Feelings About Husband Patrick

Lindsay Clancy’s modest home on Summer Street in Duxbury was once meant…