I'm not a member of this union, which makes things even worse* but a couple of things stand out from this communication:
1. That they are reporting something that happened *last* year, now, at the end of August
2. That they think that union members shouldn't be concerned because no financial information was stolen
The ICO needs to up its game and start making organisations who get hacked start paying compensation.
Not good enough. Far too casual.
*We did some scoping work for them years ago for a Discourse-based platform. No idea if it was ever implemented.