Contact us

Notification of cyber security incident

We were recently notified of a security incident affecting the provider of our database, which is provided by a company called Beacon CRM. Beacon has told us about a security incident affecting its system, and we want to explain clearly what happened, what information may have been affected, what we are doing in response, and what you can do now.

What has happened?

Beacon has informed Open Door, Branch and other organisations that use its system, that it has experienced a cyber attack. Beacon has told us that it has identified that an unauthorised person recently gained access to its database and that Beacon believes copies of some information stored there were downloaded. Beacon is still investigating the incident, so we do not yet know every detail, but we want to share what we know now clearly and transparently.

Who has been affected by this incident

This message has been sent to affected individuals by email. Where we don’t have an email address for you, you will have received a text message asking you to read this message on our website. If you have received this text message it is because, regrettably, we understand that your personal data is likely to have been included in the information affected. We will continue to review Beacon’s updates and will tell you if we receive new information that materially changes what this means for you.

What about security measures?

Beacon does have security measures in place, but these did not prevent this incident. Beacon has told us that they are now working closely with cybersecurity specialists to understand exactly what happened and to strengthen their systems. At this point, there is no evidence that any of the information has been published or used for fraud.

Beacon is providing ongoing updates about the incident, which you can read below.

What data do Open Door and Branch store in Beacon?

We take data privacy and supplier security very seriously. Open Door and Branch use Beacon to store information that people share with us when accessing our services or that organisations or individuals share with us to make sure we can keep people safe. This will include contact details, dates of birth, case notes, and any other information you have provided to us in connection with your access to our services. Case notes may include sensitive information about someone’s life, health, risk, and safeguarding, and information relating to court orders. We want to be clear about this so you understand what may have been affected.

We also hold information about donations made to support our work, from both individuals and organisations, along with the contact details linked to those donations. Beacon has told us that there is no evidence that full payment card details, card security codes or online banking information were taken. These are held in separate, secure systems.

What have Open Door and Branch done in response to the incident?

Open Door and Branch are concerned about the incident. We have reported it to the Information Commissioners Office (ICO) and the Charities Commission. We have also followed Beacon’s guidance on immediate technical steps, including updating staff passwords.
Our own internal office network and computer systems remain secure and there is no evidence that other systems storing your personal data have been affected.

What does this mean for you?

Based on the information currently available to us, we believe your personal data is likely to have been included in the information affected by this incident. We know that this may be very concerning for you.

There is currently no evidence that your information has been published or used fraudulently. As a precaution, do not click on unexpected links or open unexpected attachments in messages claiming to be from Open Door Charity, Branch, Beacon, a donation platform or HMRC about Gift Aid. We will never ask you for your full password, payment-card security code or online banking details. If you receive a suspicious message, contact us using the details in this message rather than replying to the message itself.

Please continue to contact us in your usual way, especially if you want to double check anything or have concerns.

How can we support you with this?

We are very sorry that this has happened. We want to make sure we do anything we can to ensure you feel supported after this incident, including by answering questions you may have about the incident, helping you understand what information may have been affected, and signposting you to appropriate support if this has caused distress.

If you feel you need immediate support at any point, you can contact the following services:

Adults (18+)
• Samaritans – 116 123 (24 hours a day)
• Companeros Crisis Café – 2a Price Street, Birkenhead, CH41 6JN. Open 10am–10pm, every day of the year.
• Qwell – Online mental health support: www.qwell.io

Young people (14–17)
• Samaritans – 116 123 (24 hours a day)
• Kooth – Online mental health support: www.kooth.com

Emergency help (all ages)
• 999 (emergency)
• 111 (non emergency)
• Your local A&E department

Additional support
• Shout – Text SHOUT to 85258 (24/7)
• Papyrus HOPELINE247 (for under 35s) – 0800 068 4141, text 07860 039967, or email pat@papyrus-uk.org

How to get in touch with us

We have a team of people managing our response to this incident and keeping a close eye on any updates. If you have any questions, want to check whether a message you have received from us is genuine, or want to discuss any concerns, please contact us on info@opendoorcharity.com.

You also have the right to raise concerns with the Information Commissioner’s Office, the UK regulator for data protection. We would encourage you to contact us first so we can try to help, but you can contact the ICO if you are unhappy with how we have handled this incident or your personal data.

Open Door
navigate
lets chat
sign up