Beacon data breach: A statement from Rita Waters, NYAS Group Chief Executive

NYAS uses an online system called Beacon to store various types of supporter information. Beacon is a highly regarded system used by over 1,000 charities. Unfortunately, Beacon experienced a cyber security incident last week and unauthorised access was gained to their system. 

On behalf of NYAS, I am sorry to be writing this statement, but it is important that we inform supporters of this situation as soon as possible and share this knowledge. NYAS takes the protection of all our systems, and supporters' personal information, extremely seriously.

What does NYAS use the Beacon system for? Is the data of those you support at risk? 

NYAS does not use Beacon for data related to service-delivery, but for data relating to our fundraising and marketing activity.   This means that sensitive data relating to those who receive our services is not included in this breach. For our supporters and donors, we can confirm that personal bank and payment details are also not stored within Beacon, and have therefore not been compromised by this incident. 

What actions have NYAS and Beacon taken? 
 
This breach has occurred through Beacon’s systems and not through NYAS’s own electronic systems, but we understand that this will be a concern for supporters, and we hope to reassure you that we are taking this incident seriously, working alongside Beacon’s teams. 

To understand the situation and its potential impact, Beacon has been working with external cyber-security experts to learn more, so at this stage we cannot be sure what information has been accessed, if any, but we can reassure you that the current assessment indicates the risk is not high. NYAS has reported the incident to the ICO, assessed risk to our supporters, and we are continuing to monitor any developments as Beacon's investigation progresses. 

Do supporters need to take any action? 

There is no evidence currently that NYAS supporter data has been misused as a result of this incident. However, as with any potential cyber security breaches, supporters should be vigilant and cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details can often be used for ‘phishing’ and other unsolicited communications. 

If more information is required, Beacon has a set of incident-related FAQs on their site, which you can access at this link: Incident FAQs 

Thank you to our supporters for your trust in NYAS, and for your understanding at this time.