Gambling with Lives has confirmed that its information was compromised in a cyberattack affecting third-party CRM provider Beacon. Chair of trustees Charles Ritchie said Beacon had informed the charity that unauthorised access followed compromised credentials.
“Beacon told us that compromised credentials were used to gain access to Beacon, and copies of back up files were likely downloaded by the unauthorised third party.
“Beacon has engaged specialist cyber security experts, reported the incident to the Information Commissioner’s Office (ICO), secured the system, and is continuing to investigate the incident.”

Investigation continues as charity assesses potential risks
Ritchie noted that compromised information could include names, addresses, contact details, dates of birth and donation records. Bank information was not affected. Gambling with Lives said it had assessed risks to individuals and would monitor Beacon’s investigation.
“Beacon has informed us that it has identified and addressed the vulnerability that led to the unauthorised access, reset relevant credentials, enhanced security monitoring, and implemented additional security measures across its systems.
“It has also advised that its external cyber security experts have not identified evidence of ongoing unauthorised access since the incident was contained.”

Gambling with Lives urges caution over suspicious communications
The charity advised stakeholders to stay cautious when receiving unexpected communications and support families bereaved by gambling-related suicides.
“We are grateful for your trust in Gambling with Lives and our ongoing work together. We appreciate that this news may be concerning and we sincerely apologise for any worry or inconvenience this incident may cause,” Ritchie continued.
“If our investigation identifies any further information that may affect you, we will provide an update as soon as possible.”
The cyberattack on Gambling With Lives has revealed the need for charities handling sensitive personal information to integrate a strict cybersecurity framework. The main test for the charity organisation is how quickly affected stakeholders are informed to ensure protection from harm.