25.8 C
New York
Wednesday, September 16, 2026

Cyber attack leaves a whole lot of parishioners prone to identity theft

A CYBER attack on software utilized by APCS, the corporate utilized by many dioceses to perform Disclosure and Barring Service (DBS) checks, has left a whole lot of parishioners prone to identity theft.

The Church Times has confirmed that not less than ten dioceses are affected: Derby, Ely, Guildford, Hereford, Newcastle, Oxford, Salisbury, Southwark, Winchester, and Worcester. The incident occurred around 31 July.

The diocese of Southwark confirmed on its website on Wednesday that the National Church Institutions were offering 12 months of free credit and web-monitoring services, provided by Experian, to individuals inside the Church of England affected by the breach. It said: “The Experian Identity Plus account helps detect possible misuse of non-public data and provides individuals with identity monitoring support, focused on the identification and determination of identity theft.”

Southwark incumbents were contacted by the diocese on Friday evening. The email relayed that, on 17 August, APCS had been notified by its external software supplier, Intradev, of a “recent cyber-attack”, during which personal data had been stolen. The data breach concerned data collected from December 2024 to eight May 2025. APCS had confirmed that it didn’t store payment card details or records of any criminal convictions.

APCS was “conducting a radical investigation to find out the total scope of the information involved”, the e-mail said. “It is probably going that this includes any data submitted for DBS applications within the period referred to above. APCS are only contacting data controllers (i.e. the diocese and PCCs) where they know there was an information breach. Not all PCCs will must be contacted. We have been advised by APCS that we will proceed using their services as normal.

“The potential impact on any affected individuals may include identity theft.”

The diocese itself has reported the incident to the ICO, nevertheless it has advised parishes contacted directly by APCS that they “might have to report the matter to the ICO and notify potentially affected parish officers and others for whom you’ve got carried out DBS checks”.

It also advised recipients to “remain vigilant in managing your individual personal information online to minimise any potential risk, particularly in the event you are approached by any unknown individual or organisation that will not appear real and in the event you receive any phishing emails that contain harmful links or attachments”.

The data affected are more likely to include name, date of birth, email address, postal address, hometown, gender, National Insurance number, passport details, and driving licences. Winchester diocese reported in an email to parishes that the information affected were text only — not images or documents.

On Wednesday, a Southwark diocesan spokeswoman said: “We understand that folks will likely be deeply concerned about this data breach and are doing the whole lot we will to supply clear and helpful guidance to individuals and PCCs affected.

“We are frequently updating those affected and adding any recent guidance to our website. We understand that individuals will likely be given free access to Experian’s Identity Plus credit-monitoring service and we’re working to make this available to people as quickly as possible.”

APCS describes itself as “the UK’s fastest DBS checking service”, working with greater than 19,000 organisations. Different dioceses have been informed at different times: Ely was not alerted until Saturday evening, while Winchester was contacted on Thursday of last week. DCOs confirmed that dioceses were working to support affected parishes. But advice given varies based on diocese.

A notice on the Newcastle diocese’s website clarified that “PCCs are separate data controllers and due to this fact have a responsibility to administer data breaches.”

It advised parishes to contact APCS directly “to request an update on their investigation and to grasp the extent to which individuals in your PCC could have been affected”. Those affected should consider the likely risks of identity theft and whether or to not contact individuals.

The advice from Salisbury diocese was that parishes affected should contact each the ICO and the individuals affected. The Charity Commission also needs to be told, it said, and the national Church had advised parishes to not process any more DBS checks via APCS until further notice.

The diocese of Winchester provided detailed guidance on contacting each affected individuals — including what to say — and the ICO.

The diocese of Worcester has arrange a dedicated email for support. Its advice online said that the information breach also concerned the month of November 2024.

Many dioceses confirmed to the Church Times that they were unaffected because they used the DBS checking services of Thirtyone:eight.

Concerned individuals can contact ACPS at enquiries@accesspcs.co.uk or 0343 611 2727.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

0FansLike
0FollowersFollow
0SubscribersSubscribe

Sign up to receive your exclusive updates, and keep up to date with our latest articles!

We don’t spam! Read our privacy policy for more info.

Latest Articles