These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.
A cybersecurity incident involving Beacon CRM, a cloud-based customer relationship management platform used by more than 1,000 charities and nonprofit organizations, has affected a growing number of Christian ministries and charitable organizations across the United Kingdom. Early findings indicate that attackers gained access using compromised credentials and made copies of Beacon’s database backups. Because investigators have been unable to determine exactly what data was exfiltrated, Beacon has advised customers to “assume that all data that you store in Beacon, including attachment files, has been downloaded.” Several Christian organizations, including Keswick Ministries, Operation Mobilisation (OM), Christians in Sport, Kintsugi Hope, Langham Arts, ReSource, and Living Out, notified supporters that information stored in the platform may have been exposed.
Experts noted how this third-party incident now creates notification obligations for the affected religious and nonprofit organizations. In the UK, organizations affected by the exposure of sensitive information through a vendor may be required to notify the Information Commissioner’s Office (ICO) within 72 hours, as well as applicable charity regulators. Because CRM systems often contain sensitive information such as case notes, safeguarding records, health-related correspondence, identification documents, financial information, and legacy records, a third-party breach involving these systems may require organizations to treat the incident as more than a routine supporter data exposure and consider additional reporting and notification responsibilities.
Analyst Comments: For faith-based organizations, this incident is a reminder that cybersecurity risk extends beyond an organization’s own network and into the networks of third-party vendors. Many Houses of Worship (HOWs) rely on third-party platforms to manage donor relationships, event registrations, volunteers, membership records, and fundraising campaigns. When one of those providers experiences a breach, sensitive information entrusted to a faith-based organization can become exposed even if the organization’s internal systems remain secure. The consequences extend beyond regulatory requirements and financial impacts, potentially affecting donor confidence, volunteer trust, and the reputation of the ministry.
This incident also reinforces the importance of understanding what internal information outside vendors have access to before an incident occurs. Faith-based organizations can benefit from maintaining an inventory of third-party services, limiting the amount of sensitive information stored in vendor systems when practical, and reviewing vendor security practices as part of procurement and renewal processes. Organizations can also strengthen resilience by enabling multi-factor authentication and strong credential management for connected accounts, while preparing communication plans for notifying staff, volunteers, congregants, and donors if a trusted service provider experiences a security incident. Regular reviews of vendor access, backup procedures, and incident response plans can help organizations respond more quickly and maintain confidence when third-party events affect ministry operations.
A recent case in North Carolina highlights a growing type of real estate fraud that can affect HOWs. Land intended to become the future home of West Saint Mark Church of Christ was fraudulently sold without the knowledge or consent of its owners after scammers allegedly impersonated the property owner and used forged documents to complete the transaction. The property, which had been owned by the family since the 1960s and was being prepared for church construction since 2005, was sold for $110,000 before the fraud was discovered. Timothy Peppers only learned something was wrong after receiving a letter from a law firm stating it had been hired to handle the sale of his own property. Upon reviewing the paperwork, he immediately recognized that the signatures were fraudulent, stating, “That’s not my signature, and my mother’s deceased.” His mother, whose signature appeared on the documents, had died in 2021. The attorney involved later confirmed their client had also been deceived by someone impersonating Peppers, and the property was ultimately transferred back into the church’s ownership.
The incident reflects a broader trend that has prompted warnings from the FBI. Criminals are increasingly targeting vacant or undeveloped properties by stealing owners’ identities, forging deeds or sale documents, and completing transactions before the legitimate owner becomes aware. Officials recommend property owners enroll in county property fraud alert programs through their county’s Register of Deeds office, regularly review property records, pay particular attention to land that is rarely visited, and immediately report suspicious activity.
Analyst Comments: Many churches, ministries, camps, cemeteries, and retreat centers own vacant parcels of land, future expansion sites, or properties that may not receive regular attention, making them attractive targets for identity-based real estate fraud. Unlike vandalism or theft, fraudulent property transfers can go unnoticed until construction begins, taxes are affected, or legal documents arrive, creating significant financial costs, project delays, and legal challenges.
Houses of worship can reduce this risk by maintaining accurate ownership records, limiting who has authority over property transactions, enrolling in county deed or property fraud notification services where available, periodically reviewing public land records, and including property ownership verification as part of routine governance or risk management activities. This case also highlights the importance of coordination between church leadership, legal counsel, and county officials so that suspicious activity is identified and addressed before it develops into a lengthy legal dispute.
The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.