Cornwall charities warned over donor data after 1,000-charity hack
If you have ever donated to a charity online, bought a ticket to a fundraiser or signed up for a membership, your details are sitting in a database somewhere. A specialist with an office in Truro says those databases are easier to get into than most donors would like to think.
Your daily dose of Cornwall
News, events and goings on across the Duchy
One key was all it took
The warning comes from Siobhan Holmes, a partner at accountancy and business advisory firm Azets, who specialises in not-for-profit organisations. She is urging charities in Cornwall to strengthen their cyber security after a customer relationship management (CRM) platform used by more than 1,000 charities through a single technology provider was breached.
Charities use a CRM, either in-house or through a technology provider, to collect donations online, sell event tickets, manage memberships and email updates to supporters.
According to Siobhan, a single compromised AWS access key was enough to enable the attack. An AWS access key is a security credential that verifies who you are and whether you have permission to get under the bonnet of a computer programme.
“Although the data was encrypted at rest, the attacker used valid credentials to access and download information in a readable form,” she said.
“Encryption alone is not enough. Strong identity and access management are equally vital.”
Why charities are a target
Siobhan said the hack shows “just how dependent the fundraising sector has become on shared technology providers”.
“For hackers, many charities have an ‘Achilles’ heel’ when it comes to IT, shooting their virtual arrows through thin firewalls to wreak havoc,” she said.
“Charities do need to significantly strengthen their cyber security to avoid customer data being stolen and used to commit financial fraud such as taking out credit cards or loans in the names of donors.”
She pointed to the scale of the sector. Registered charities in the UK had a total income of £102 billion in 2024/25, with millions of people on their databases. In her words, that makes the sector “a soft target with the prospect of rich customer data pickings”.
Size matters too. Micro and small charities, with incomes of less than £10,000 and up to £100,000 respectively, make up around 75% of the sector.
“The risk of being in the crosshairs of cyber thieves is therefore even higher because many charities simply cannot afford to make their CRMs as impregnable as they can be,” Siobhan said.
What trustees are being told to do
Siobhan’s advice is aimed at the people who run charities, including trustees, executives and finance leaders.
- Ask about suppliers as well as your own systems. She said the breach should prompt charities to ask how secure the suppliers and platforms they rely on are.
- Treat it as a governance issue. “Cyber resilience must be viewed as a fundamental part of governance, risk management and safeguarding public trust,” she said.
- Put it on the board agenda. “Cyber security should not only be a key item on the risk register, but it should also be a standing item for Board meetings to ensure strong governance and challenge by the trustees.”
- Review credentials and access controls. She said the breach demonstrated “the critical importance of credential management and access controls”.
- Get professional advice. “Charities with CRMs need to urgently review cyber security and seek professional advice. It is not something that can be scrimped on.”
She said protecting beneficiaries, donors and sensitive data “is no longer solely the responsibility of IT teams”, and that it falls to the people in charge of a charity, including trustees “who perhaps are out of their depth when it comes to IT”.
“If major corporate brands such as Jaguar Land Rover and M&S can be hit, so can charities,” she added.
Registered charities in the UK have 1.7 million employees, 6.5 million volunteers and more than 921,000 trustees, according to the figures supplied by Azets.
Earlier this year Siobhan urged charities and not-for-profit organisations to make sure their procedures and records are watertight in light of new and intensified compliance activity by HMRC.
Read Next
- EnvironmentFrom the top of the cliff path, there was nothing to see.
Share This Story, Choose Your Platform!
To keep up with the latest cornish news follow us below
Follow CornishStuff on Facebook - Like our Facebook page to get the latest news in your feed and join in the discussions in the comments. Click here to give us a like!
Follow us on Twitter - For the latest breaking news in Cornwall and the latest stories, click here to follow CornishStuff on X.
Follow us on Instagram - We also put the latest news in our Instagram Stories. Click here to follow CornishStuff on Instagram.
- 1
- 2
- 3
- 4
- 5
- 6









