Details of Incident
The Royal Society for the Support of Women of Scotland (RSSWS) uses a database system from a company called Beacon CRM to store and manage the information relating to both the women who we support (or have supported in the past), and those who have applied to us for support.
Beacon informed us on 3rd August that it experienced a cyber security incident at the end of July in which an unauthorised third party gained access to its systems. They immediately took steps to investigate and secure their system, but they now tell us that information held on their system on 27th July, including attached files, is likely to have been stollen in a readable format. Any information added to Beacon after this date remains secure we are assured the live system remains safe and secure as Beacon is a trusted and reputable company with ISO 27001:2022 and Cyber Essentials Plus certifications (leading global standards for information security). For more details please see https://www.beaconcrm.org/incident.
What we have done
Although this breach wasn’t caused by RSSWS, we have
- Notified all people whose information may have been affected to make them aware of the risks
- Notified the Information Commissioner’s Office (who have told us that they do not plan on taking further action)
- Started a process of reviewing our own cyber security measures and data protection impact assessment to ensure these are robust.
- Paused new applications to the Society while we investigated, but we have now re-opened these and eligible women can now apply as normal via this page.
Keeping safe from scams
While there is currently no evidence that any of this information has been published or misused, our advice is that anyone who has been in contact with RSSWS in the past should:
- Monitor their bank account for unusual activity.
- Be cautious of unexpected emails, texts or phone calls.
- Consider changing passwords regularly and never share passwords, security codes or banking details in response to unsolicited communications.
- Contact their bank immediately if they notice suspicious transactions.
People can also reliably get advice and information from:
- The National Cyber Security Centre has guidance on how to protect themselves from the impact of data breaches – see https://www.ncsc.gov.uk/guidance/data-breaches.
- CIFAS(the UK’s Fraud Prevention Service) provides information and offers protective registration via the National Fraud Database – see https://www.cifas.org.uk/individuals
- Age Scotland has information online on staying safe from scams - see https://www.agescotland.org.uk/information-advice/staying-safe-online. They also run a helpline 0800 12 44 222
- Their local Citizens Advice Bureau.
Date of information
This information on the incident was updated on 17th August 2026, and we will update it further if additional information becomes available.