More information for our supporters

Q: What exactly happened? 

A: Beacon, our CRM (Customer Relationship Management) software provider experienced a cyber-security incident in which an unauthorised third party gained access to their systems on Wednesday 29 July. Campaign for National Parks was alerted to this on Monday 3 August. Beacon has taken immediate action to secure its systems and prevent any further unauthorised access. There is currently an investigation underway to ascertain what data has been accessed. 

Q: What is Beacon used for? 

We use Beacon to store audience details, and track their interaction with us (e.g. donations, signing a petition, attending an event). Beacon is used by over 1,500 charities as their CRM. 

Q: How did this happen? 

A: Beacon is currently investigating the full circumstances of the incident with external cyber-security specialists, but their current understanding is that compromised credentials were used to gain access to Beacon. 

Q: What data was accessed? 

A: Their investigation into the scope of data that may have been accessed is ongoing. At this stage, they understand copies of database backups were made. Whilst the copying or taking of that data hasn’t yet been confirmed, the evidence they have so far suggests these copies were likely downloaded.  

No financial information has been compromised such as card or bank account details, but rather personal details you may have shared with us. There is currently no evidence that this data has been shared on the dark web and there has been no ransom request. 

Q: What does this mean for me? 

A: We are making you, and all people on our CRM system, aware of the incident so that you can remain vigilant. You should be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications. 

Q: What is Campaign for National Parks doing? 

A: We have our own policies in place as well as GDPR compliance which we have taken immediate action on including contacting the ICO (Information Commissioners Office). We are also liaising with Beacon and monitoring their own investigation with the help of cyber-security specialists. We anticipate this may take some time so have contacted anyone we hold data for as a precaution at this time. 

Q: What happens next? 

A: We will contact everyone on our CRM again if we have confirmation that data has been shared from Beacon. It’s best to remain vigilant about unexpected phone calls, messages, emails, links or requests for personal information. Take Five To Stop Fraud has excellent advice on protecting yourself against scams. 

 

We are very sorry for any concern this may cause. If you would like to speak to a staff member about the data we hold about you, or if you would like further information about this matter, please don’t hesitate to get in touch. You can email us at [email protected].