Sheffield Hospitals Charity: Hospital charity supporters hit by cyber attack

Sheffield Hospitals Charity: Hospital charity supporters hit by cyber attack

Sheffield Hospitals Charity Reports Data Breach Affecting Supporters

Sheffield Hospitals Charity, an independent organization raising £2.5 million annually to support NHS hospitals and healthcare services in Sheffield, has disclosed a cybersecurity incident involving unauthorized access to its systems. The breach, detected on Monday, targeted Beacon CRM, the charity’s secure database used to manage supporter information, including names, contact details, donation records, and Gift Aid data. Payment card details were not stored in the affected system.

An unauthorized individual gained access using compromised login credentials and downloaded database backups. While there is currently no evidence that personal data has been misused or published, the charity has taken precautionary steps to notify affected individuals. The exact number of people impacted has not been disclosed.

The charity has engaged specialist cybersecurity experts to investigate the incident and has reported it to the Information Commissioner’s Office (ICO), Charity Commission, and Gambling Commission. Immediate measures were taken to secure systems and contain the breach. Chief Executive Beth Crackles issued an apology, emphasizing the organization’s commitment to addressing the matter.

Sheffield Hospitals Charity operates separately from the NHS and does not hold patient data. However, supporters are advised to remain vigilant against potential phishing attempts or suspicious communications. The investigation into the full scope of the breach is ongoing.

Source: https://www.bbc.com/news/articles/cgq5z9ggqeyo

Sheffield Hospitals Charity cybersecurity rating report: https://www.rankiteo.com/company/sheffield-hospitals-charity

"id": "SHE1785947040",
"linkid": "sheffield-hospitals-charity",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare/Non-Profit',
                        'location': 'Sheffield, UK',
                        'name': 'Sheffield Hospitals Charity',
                        'type': 'Charity'}],
 'attack_vector': 'Compromised login credentials',
 'customer_advisories': 'Supporters advised to remain vigilant against '
                        'potential phishing attempts or suspicious '
                        'communications',
 'data_breach': {'data_exfiltration': 'Database backups downloaded',
                 'personally_identifiable_information': 'Names, contact '
                                                        'details, donation '
                                                        'records, Gift Aid '
                                                        'data',
                 'sensitivity_of_data': 'Personally identifiable information '
                                        '(PII)',
                 'type_of_data_compromised': 'Supporter information'},
 'date_detected': '2023-10-02',
 'description': 'Sheffield Hospitals Charity disclosed a cybersecurity '
                'incident involving unauthorized access to its systems. The '
                'breach targeted Beacon CRM, the charity’s secure database '
                'used to manage supporter information, including names, '
                'contact details, donation records, and Gift Aid data. An '
                'unauthorized individual gained access using compromised login '
                'credentials and downloaded database backups.',
 'impact': {'data_compromised': 'Names, contact details, donation records, '
                                'Gift Aid data',
            'identity_theft_risk': 'Potential',
            'payment_information_risk': 'None (payment card details not '
                                        'stored)',
            'systems_affected': 'Beacon CRM'},
 'initial_access_broker': {'entry_point': 'Compromised login credentials'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'Sheffield Hospitals Charity Public Disclosure'}],
 'regulatory_compliance': {'regulatory_notifications': ['Information '
                                                        'Commissioner’s Office '
                                                        '(ICO)',
                                                        'Charity Commission',
                                                        'Gambling Commission']},
 'response': {'communication_strategy': 'Notification to affected individuals, '
                                        'public disclosure',
              'containment_measures': 'Immediate measures to secure systems '
                                      'and contain the breach',
              'third_party_assistance': 'Specialist cybersecurity experts'},
 'title': 'Sheffield Hospitals Charity Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.