What has happened?
Options has been informed by Beacon CRM, the system we use to manage supporter information, that it recently experienced a cyber security incident involving unauthorised access to its systems. Beacon’s investigation suggests copies of database backups were likely downloaded by an unauthorised third party.
Was Options directly hacked?
No. The incident occurred at Beacon CRM, one of our trusted service providers. However, because we hold supporter information within Beacon, some of your personal data may have been affected.
What information about me may have been involved?
Depending on the information you have shared with us, this may include:
- Your name
- Postal address
- Email address
- Telephone number
- Donation history
The exact information varies between supporters.
Were my bank details or payment card details affected?
No. We do not store payment card details within Beacon CRM. Based on the information currently available, there is no evidence that card payment information or bank account details have been compromised through this incident.
Is there any evidence that my information has been misused?
At present, there is no evidence that personal information from this incident has been published online or misused. Beacon has stated that it is actively monitoring for any signs of data appearing on the dark web.
What should I do now?
We recommend that you:
- Be cautious of unexpected emails, texts, phone calls, or social media messages.
- Do not share passwords, security codes, or financial information.
- Avoid clicking links or opening attachments from unknown or suspicious sources.
- Contact us directly if you receive a message that claims to be from Options but seems suspicious.
Does this mean my email account or bank account has been accessed?
No. This incident does not provide access to your personal email account, online banking, or passwords. However, cyber criminals may use contact information to send convincing phishing messages, so it is important to remain vigilant.
What is Options doing about this?
We have:
- Assessed the information we hold within Beacon CRM.
- Reviewed guidance provided by Beacon and the ICO.
- Considered our obligations under UK data protection legislation.
- Continued to monitor updates from Beacon as its investigation progresses.
- Taken steps to ensure our own systems remain secure.
Protecting your information remains a priority for us.
Has this incident been reported to the authorities?
Beacon has confirmed that it is working with law enforcement and relevant regulators. Organisations using Beacon are also reviewing their own reporting obligations and taking appropriate action where required.
Will I be updated if new information emerges?
Yes. We are committed to being transparent. If Beacon’s investigation identifies any significant developments that affect your information, we will provide further updates as appropriate.
Who can I contact if I have questions?
If you have any questions or concerns about this incident, please contact:
email: welcome@optionsempowers.org.uk
call: 0151 236 0855