A girl wearing glasses sitting on the end of her bed while using her laptop.

Cyber security incident

  • 6 min read
  • 20 July 2020

Author: YoungMinds Data Team

21 July 2020

(last updated 16 November)

We were notified late on Thursday 16th July about a criminal attack on Blackbaud’s servers in May. Blackbaud are the company that host our supporter database, and the database of several other charities. This has therefore meant that some details of our supporters have been accessed, including some personal information like their names, addresses and email addresses.

As a matter of urgency we have sought confirmation about the steps Blackbaud have taken to manage the situation. They have informed us that, to the best of their knowledge, all of the details that were accessed have now been destroyed. They have also reassured us that new safeguards have been put in place to prevent this happening again. We have decided to report this incident to both the ICO and Charity Commission at the earliest opportunity to ensure that they are fully aware.

We have been assured by Blackbaud that there is a low risk to YoungMinds’ supporters, but all the same we would urge all of our supporters to continue to be wary of unexpected communication and practise the usual caution around suspicious emails and letters.

If anyone is concerned or has further questions please contact our data protection lead at: dataprotectionmanager@youngminds.org.uk

Blackbaud has set out further details about the incident here.

We take data security seriously. Our privacy notice details how we use your data, how we keep it safe and how to opt out of data processing activities. View our privacy policy here.

We were notified late on Thursday 16th July about a criminal attack on Blackbaud’s servers in May. Blackbaud are the company that host our supporter database, and the database of a large number of other organisations. This has therefore meant that some details of our supporters have been accessed, including some personal information like their names, addresses and email addresses.

As a matter of urgency we have sought confirmation about the steps Blackbaud have taken to manage the situation. They have informed us that, to the best of their knowledge, all of the details that were accessed have now been destroyed. We are aware that they have paid a ransom to the cybercriminals for assurances that the stolen information has been destroyed. They have worked with law enforcement and a third-party company and have found no evidence that any of the information taken has been used, and continue to monitor for this.

They have informed us that new safeguards have been put in place to prevent this happening again.

The database that was affected includes supporters’ contact details (which may include phone number, email address and/or postal address) and some details of the nature of their activity with us, including if they have donated money, purchased a publication or signed a petition.

At the earliest opportunity, YoungMinds took action to report the breach to the Information Commissioners Office and took advice from a company specialising in data management and data breaches. Additionally, we submitted a Serious Incident Report to the Charity Commission. We also made a statement about the breach on our website. We continue to seek clarity from Blackbaud about how the breach occurred and confirmation of which data may have been accessed, and will notify individuals if it appears that sensitive data has been accessed. We have also consulted with our IT service provider to ensure that our internal systems are secure.

Blackbaud have assured us that to the best of their knowledge the data has been destroyed, and their ongoing monitoring has shown no sign of any of the information being used fraudulently. We continue to monitor the situation and seek independent advice.

We would recommend to all supporters to continue to take the usual steps maintaining caution. More information about protecting against fraud can be found here by the Met police.

No. Any potentially sensitive data about young people is kept securely on a different database. Therefore this information was not accessed.

This database was not used to process financial information or store banking or credit card details about supporters. These details are stored securely on a separate database that was not affected by the breach. As part of our ongoing investigation into this incident, we’ve discovered a very small number of financial documents held on the database hosted by Blackbaud, which have now been removed. Having consulted with both the ICO and our Legal Advisors, we remain confident that the risk to our supporters remains extremely low.

No. Blackbaud have also contacted us to confirm that we were not part of the subset that was referred to.

Spread the word