Macmillan Jersey and Beacon CRM: Warning after cancer charity hit by cyber security incident

Macmillan Jersey and Beacon CRM: Warning after cancer charity hit by cyber security incident

Macmillan Jersey Alerts Supporters After Cybersecurity Incident Involving CRM Provider

Macmillan Jersey, a local cancer charity, has notified supporters, donors, and volunteers of a potential data exposure following a cybersecurity incident involving its customer relationship management (CRM) system. The breach was discovered on [date not specified] after software provider Beacon CRM reported unauthorized access to backup copies of customer databases.

While the investigation remains ongoing, Beacon has advised its clients including Macmillan Jersey to assume that data stored in the affected CRM may have been compromised. The charity confirmed that no evidence of misuse has been found to date and emphasized that payment card details were not exposed, as donations are processed securely through JustGiving. Additionally, health records, counselling notes, and clinical data were unaffected, as these are stored separately.

The compromised database primarily contained contact details, communication preferences, and records of supporters, donors, volunteers, and event participants. Macmillan Jersey has activated its data protection protocols and notified the Jersey Office of the Information Commissioner, fulfilling its legal obligations. Beacon has since engaged independent cybersecurity specialists and secured its systems, though investigations continue.

In a statement, Senior Operations Lead Kevin Alway apologized for the concern caused, reiterating the charity’s commitment to safeguarding personal data. While no immediate action is required from affected individuals, Macmillan Jersey advised caution against suspicious emails or unsolicited requests for passwords or financial information. The charity will provide further updates if the investigation uncovers heightened risks.

For inquiries, supporters can contact mydata@macmillanjersey.com or call 01534 498189.

Source: https://www.bailiwickexpress.com/news/warning-after-cancer-charity-hit-by-cyber-security-incident/

Macmillan Jersey TPRM report: https://www.rankiteo.com/company/macmillan-cancer-support-jersey

Beacon CRM TPRM report: https://www.rankiteo.com/company/beaconcloudtech

"id": "beamac1785853582",
"linkid": "beaconcloudtech, macmillan-cancer-support-jersey",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Supporters, donors, volunteers, '
                                              'and event participants',
                        'industry': 'Non-Profit/Healthcare',
                        'location': 'Jersey',
                        'name': 'Macmillan Jersey',
                        'type': 'Charity'},
                       {'industry': 'Technology/CRM',
                        'name': 'Beacon CRM',
                        'type': 'Software Provider'}],
 'customer_advisories': 'No immediate action required; advised to remain '
                        'vigilant against suspicious communications',
 'data_breach': {'personally_identifiable_information': 'Yes (contact details)',
                 'sensitivity_of_data': 'Low to moderate (no health records, '
                                        'counselling notes, clinical data, or '
                                        'payment card details)',
                 'type_of_data_compromised': 'Personal data (contact details, '
                                             'communication preferences)'},
 'description': 'Macmillan Jersey, a local cancer charity, notified '
                'supporters, donors, and volunteers of a potential data '
                'exposure following a cybersecurity incident involving its '
                'customer relationship management (CRM) system. The breach was '
                'discovered after software provider Beacon CRM reported '
                'unauthorized access to backup copies of customer databases.',
 'impact': {'data_compromised': 'Contact details, communication preferences, '
                                'and records of supporters, donors, '
                                'volunteers, and event participants',
            'identity_theft_risk': 'Potential risk due to exposure of personal '
                                   'data',
            'payment_information_risk': 'None (payment card details were not '
                                        'exposed)',
            'systems_affected': 'Beacon CRM (customer relationship management '
                                'system)'},
 'investigation_status': 'Ongoing',
 'recommendations': 'Caution against suspicious emails or unsolicited requests '
                    'for passwords or financial information',
 'references': [{'source': 'Macmillan Jersey Statement'}],
 'regulatory_compliance': {'regulatory_notifications': 'Jersey Office of the '
                                                       'Information '
                                                       'Commissioner notified'},
 'response': {'communication_strategy': 'Public statement issued to '
                                        'supporters, donors, and volunteers; '
                                        'advisory against suspicious emails or '
                                        'unsolicited requests',
              'containment_measures': 'Systems secured by Beacon CRM',
              'incident_response_plan_activated': 'Data protection protocols '
                                                  'activated',
              'third_party_assistance': 'Independent cybersecurity specialists '
                                        'engaged by Beacon CRM'},
 'stakeholder_advisories': 'Advisory to supporters, donors, and volunteers '
                           'regarding potential data exposure and caution '
                           'against phishing attempts',
 'title': 'Macmillan Jersey Cybersecurity Incident Involving CRM Provider',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.