Cyber Incident Victim: Christians Against Poverty
Date:
Jul 2016
Location:
United Kingdom
Summary
A UK debt relief charity suffered a data breach when unidentified hackers infiltrated its systems through a sophisticated external attack, compromising supporter and client information including names, addresses, email and phone numbers, as well as bank account details and sort codes. The intrusion was detected approximately one week after it began, prompting the organization to engage IT security experts, notify law enforcement, and report the incident to national data protection authorities. While the charity emphasized its systems were well-protected, it acknowledged the potential risk of phishing targeting affected individuals and initiated direct communications with current and former stakeholders to alert them of the exposure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In late July 2016, unidentified hackers breached the computer systems of UK debt relief charity Christians Against Poverty (CAP). The intrusion compromised some but not all of the charity's systems, exposing personal details of supporters and clients—both current and former. The compromised data included names, addresses, email addresses, phone numbers, and sensitive banking information such as account numbers and sort codes. CAP detected suspicious activity on August 1, 2016, approximately one week after the initial breach. The charity immediately engaged external IT security experts to investigate, who confirmed the incident was a sophisticated external attack despite CAP’s existing server protections. CAP publicly disclosed the breach on August 4 via an online alert and began notifying affected individuals through direct communications, including email notices sent to supporters and vulnerable families the charity assisted with debt management.

The breach raised concerns about potential phishing risks for those whose data was exposed, though CAP did not confirm whether the compromised banking details were encrypted or clarify why it retained such sensitive information. The charity reported the incident to the UK Information Commissioner’s Office (ICO) and collaborated with law enforcement and cybersecurity experts to investigate the attack. In public statements, CAP emphasized taking "all possible steps" to secure its systems but provided no technical specifics about containment measures or the attackers’ methods. The organization issued FAQs to address concerns, acknowledging heightened risks while urging vigilance among affected parties. No further details regarding the scope of impacted records, financial losses, or long-term consequences were disclosed in the initial response phase.
