Historic Cathedral Hit by Cyber Attack

0
1

Key Takeaways

  • Beacon CRM reported a cyber‑security incident involving unauthorised access to its systems that process supporter and leisure‑centre data for customers such as Lincoln Cathedral and Magna Vitae.
  • The exposed information includes names, addresses, email addresses and phone numbers; payment or bank‑account details were not stored in the affected systems.
  • Both organisations confirmed they have reported the breach to the Information Commissioner’s Office (ICO) and are working with Beacon CRM to investigate and mitigate any impact.
  • Beacon CRM engaged external cyber‑security experts, contained the incident, and says there has been no service interruption; customers can continue to use the platform normally.
  • The ICO is assessing the reports and reminds organisations that personal‑data breaches must be notified within 72 hours when they pose a risk to individuals’ rights and freedoms.

Background on Beacon CRM and Its Customers
Beacon CRM is a software provider that offers donor‑management and membership‑tracking solutions to more than 1,000 charities and public‑sector organisations across the UK. Among its clients are Lincoln Cathedral, which uses the platform to maintain contact details of supporters, and Magna Vitae, the leisure‑centre operator serving Skegness, Horncastle, Mablethorpe and Louth. The software stores personal data such as names, postal addresses, email addresses and telephone numbers, and for Magna Vitae it may also capture event attendance, festival engagement records, and equality, diversity and inclusion information. Importantly, Beacon CRM stresses that neither payment card details nor bank‑account information are held in the systems involved in the incident.


Discovery of the Unauthorised Access
On Monday 3 August, Beacon CRM detected unauthorised access to the servers that process data on behalf of its customers. The company immediately activated its incident‑response plan, bringing in external cyber‑security specialists to contain the breach and begin a forensic investigation. Beacon CRM disclosed that, at the time of detection, there was no evidence that any of the accessed data had been published online, leaked to the dark web, or used in a ransom‑ware demand. The firm also confirmed that its core services remained operational, with no noticeable downtime for customers.


Statement from Lincoln Cathedral
Lincoln Cathedral was notified by Beacon CRM of the incident on the same day it was discovered. The Very Reverend Dr Simon Jones, Dean of Lincoln, emphasised that while the breach occurred within a third‑party system rather than the Cathedral’s own IT infrastructure, the institution treats the protection of personal information with the utmost seriousness. Lincoln Cathedral affirmed that it is cooperating fully with Beacon CRM’s investigation, has reported the matter to the Information Commissioner’s Office, and is taking all appropriate steps to safeguard the data entrusted to it by supporters and visitors.


Statement from Magna Vitae
Magna Vitae, which runs leisure centres in several Lincolnshire towns, issued an email to its users explaining that the data stored in Beacon CRM varies by individual and may include contact information, event attendance records, SO Festival engagement details, and equality, diversity and inclusion data. The organisation reiterated that there is currently no sign that the data has been disseminated elsewhere, but it urged recipients to remain vigilant against phishing attempts, suspicious links, or unexpected attachments. Like Lincoln Cathedral, Magna Vitae has notified the ICO and is working closely with Beacon CRM to monitor the situation.


Regulatory Response and Legal Obligations
Both Lincoln Cathedral and Magna Vitae have filed formal reports with the Information Commissioner’s Office, classifying the event as a personal‑data breach under the UK GDPR. The ICO confirmed it has received multiple reports from affected organisations and is in direct contact with Beacon Apps Ltd (the legal entity behind Beacon CRM) to assess the scope and potential impact. Under data‑protection legislation, organisations must notify the ICO within 72 hours of becoming aware of a breach that is likely to risk individuals’ rights and freedoms; failure to do so can result in significant fines and enforcement action.


Beacon CRM’s Ongoing Communication and Support
In a public statement, Beacon CRM expressed understanding that the incident is concerning for its customers and affirmed that it is treating the matter with the highest priority. The company said it has already spoken with all affected clients to keep them informed and is focusing on providing support for any onward communication those organisations may need to issue to their own stakeholders. Beacon CRM also highlighted that, beyond the immediate containment actions, there has been no interruption to its platform or services; customers continue to access the system and use its features as normal.


Implications for the Wider Charity and Public‑Sector Sector
The incident underscores the growing vulnerability of third‑party software providers that handle large volumes of personal data on behalf of numerous organisations. Charities, leisure‑centre operators, and other public‑sector bodies often rely on cloud‑based CRM solutions to streamline supporter engagement, but this dependency also creates a single point of failure. The breach serves as a reminder for organisations to conduct regular due‑diligence on vendors, review data‑processing agreements, and ensure that robust incident‑response plans are in place—not only internally but also with their service providers.


Advice for Individuals Whose Data May Be Affected
While Beacon CRM and its customers have stated there is no evidence of data misuse, individuals whose contact details were stored in the affected systems should remain cautious. Recommended steps include monitoring email accounts for unexpected or suspicious messages, avoiding clicking on links or opening attachments from unknown senders, and considering the use of multi‑factor authentication where available. If any unusual activity is detected, individuals should report it promptly to the relevant organisation and, if necessary, to Action Fraud or the ICO.


Conclusion
The cyber‑security incident at Beacon CRM highlights the importance of vigilance in an era where data is increasingly managed by external service providers. Lincoln Cathedral and Magna Vitae have responded swiftly by notifying regulators, engaging with the vendor, and advising their users to stay alert. As the ICO’s assessment progresses, the case will likely contribute to broader discussions about data‑protection standards, vendor accountability, and the need for resilient cyber‑defences across the charitable and public‑sector landscape. Until further details emerge, affected organisations and individuals are encouraged to follow the guidance provided and maintain good cyber‑hygiene practices.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here