Important message about a data security incident
On Monday 3 August Edinburgh Dog & Cat Home was notified about a cyber-security incident involving Beacon, a third-party CRM (Customer Relationship Management) provider used by the Home.
Beacon has advised us that compromised credentials were used to gain unauthorised access to its systems and copies of database backups were made. Beacon has engaged external cyber-security specialists and is continuing to investigate the incident.
The information we hold in Beacon does not include payment details or special category personal data, such as information relating to racial or ethnic origin or sexual orientation.
Beacon has advised that it is unlikely to be possible to establish exactly which information was downloaded or who it relates to. We are therefore taking a precautionary approach and treating all data held in Beacon as potentially affected.
We take the security and privacy of personal information extremely seriously. We have reported the incident to the Information Commissioner’s Office (ICO) and have taken steps to protect the information we hold.
We are contacting individuals who are potentially impacted and will provide further updates when we have more information.
Please see our FAQs below for further information.
What happened?
On Monday 3 August, we were notified by Beacon our CRM (Customer Relationship Management) software provider than an unauthorised third party gained access to their systems. They immediately engaged experts to help secure their systems and we are working closely with them to understand more about what happened.
Beacon has advised us that copies of backups were made, and the evidence suggests this data was downloaded. As it is unlikely that we will be able to establish exactly what information was downloaded or who it relates to, we are taking a precautionary approach and treating all data held in Beacon as potentially affected.
Has my data been stolen?
We cannot currently confirm that any individual’s data has been stolen or misused. Beacon has advised us that copies of backups were made, and the evidence suggests this data was downloaded. As it is unlikely that we will be able to establish exactly what information was downloaded or who it relates to, we are taking a precautionary approach and treating all data held in Beacon as potentially affected.
We do not store payment details, such as credit or debit card data or special category personal data, such as information relating to sexual orientation or racial or ethnic origin.
How many people have been affected?
We are unable to confirm exactly how many individuals may be affected. Beacon has advised that it is unlikely to establish exactly which information was downloaded or who it relates to. We are therefore taking a precautionary approach and treating all data held in Beacon as potentially affected.
What information was stolen?
We cannot currently confirm that any individual’s data has been stolen or misused. The information we hold in Beacon may include names, addresses, email addresses, telephone number, pet names where known, details of past gifts, and records of interactions with the Home.
We do not store payment details, such as credit or debit card data or special category personal data, such as information relating to sexual orientation or racial or ethnic origin.
We are taking a precautionary approach and treating all data held in Beacon as potentially affected.
Has the Information Commissioner’s Office been informed?
We have informed the ICO and are taking further advice on the appropriate next steps.
Were people who surrendered animals affected?
People who have contacted us about surrendering an animal may have information held within our CRM. Beacon has advised that it is unlikely to establish exactly which information was downloaded or who it relates to. We are therefore taking a precautionary approach and treating all data held in Beacon as potentially affected.
Were people who applied for a pet affected?
People who have contacted us about adopting an animal may have information held within our CRM. Beacon has advised that it is unlikely to establish exactly which information was downloaded or who it relates to. We are therefore taking a precautionary approach and treating all data held in Beacon as potentially affected.
Were donors affected?
People who have donated to us previously may have information held within our CRM. Beacon has advised that it is unlikely to establish exactly which information was downloaded or who it relates to. We are therefore taking a precautionary approach and treating all data held in Beacon as potentially affected.
Has my card/financial information been stolen
No financial payment or card details are stored in Beacon.
Do I need to do anything?
At this stage there is no specific action you need to take. However, we recommend that you remain alert to unexpected emails, text messages and telephone calls that ask you to provide personal information, make a payment or click on a link.
We will never ask you to provide password or payment details by link. If you receive any suspicious communication please do not respond. If you are unsure a communication is from us, you can phone us on 0131 669 5331 or email [email protected] to confirm.
I would like to complain
If you would like to submit a formal complaint please click here for more information on how to do this.