Late last week, we became aware that we may have experienced a cyber-security incident. We immediately engaged external cyber-security experts to help us investigate and secure our systems. Our current understanding is that compromised credentials were used to gain access to Beacon, and copies of our database backups were made. Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded.
This page is for customers and free-trial users who held a Beacon account before 4am GMT / 5am BST on Monday 27th July 2026.
We appreciate that you will want to consider your own obligations as a result of this issue. However, we have provided the information below to help you identify the next steps to take. This is not legal advice and is not an exhaustive list of what you should do, but we want to guide you through a process which might be new to you.
We have brought other Beacon team members into our support team and will endeavour to respond to queries that you have as quickly as possible. To ensure that we are able to answer any additional questions as quickly as possible, please appoint a single lead contact to collate any questions and direct all communication to Beacon through this person. Please ensure that you read and action, where required, all of the information below before you get in touch with Beacon.
Revoking app integrations and API keys fully in Beacon.
It is likely that your organisation will have relevant internal policies that you should find, read and follow. Whilst not an exhaustive list, you should look for your documents covering:
You are the “Controller” of the data that you store within Beacon. As such, you will need to consider whether the incident meets the threshold for you to report it to the ICO. A personal data breach should be reported to the ICO unless it is unlikely to result in a risk to the rights and freedoms of individuals. Whether there is a risk will depend on the nature of the data that was stored in Beacon, and so will vary from organisation to organisation.
Please read the information provided by the ICO to help you assess whether you need to report this breach here.
If you think that you may meet the threshold for reporting, you can complete a self-assessment on the ICO website here.
If you are a registered charity, you also need to consider whether the incident meets the threshold for reporting to the relevant charity regulator. We have provided links to helpful guidance below:
If you determine that the incident meets the threshold for reporting to the ICO, you will need the following information:
Description of the nature of the personal data breach
On Wednesday 29th July 2026, Beacon, our CRM software provider, became aware that they may have experienced a cyber-security incident. They immediately engaged external cyber-security experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of our database backups were made. We were notified by Beacon that they discovered this incident on Monday 3rd August.
Description of the likely consequences of the personal data breach
Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence Beacon has so far suggested these copies were likely downloaded. There is currently no evidence that this data has been shared on the dark web and there has been no ransom request.
Description of the measures taken, or proposed to be taken, to deal with the personal data breach and, where appropriate, of the measures taken to mitigate any possible adverse effects.
Beacon has implemented immediate measures to secure its systems and prevent any further unauthorised access. They are now:
We will now review to decide whether the incident is likely to result in a high risk to the rights and freedoms of individuals and, if so, we will inform those concerned directly and without undue delay.
The name and contact details of the data protection officer (if your organisation has one) or other contact point where more information can be obtained
You only need to contact affected individuals directly if there is likely to be a high risk to their rights and freedoms. This is a higher threshold than for notification to the ICO.
If a breach is likely to result in a high risk to the rights and freedoms of individuals, the UK GDPR (data protection law) says you must inform those concerned directly without undue delay.
The ICO has some helpful guidance that can help you make this determination:
Alternatively, you can speak to the ICO by telephone or live chat here.
If you have an existing email tool (e.g. MailChimp or Dotdigital):
- Upload the names and emails into a new audience - do not add them into any existing marketing lists
Bcc through your existing inbox:
Outlook (Exchange Online / Microsoft 365 Business)
- 500 recipients per email
- 10,000 per 24-hour period
- 500 external recipients per email
- 2,000 per 24-hour period
Use a free mass emailing tool such as:
- Sender provides a free service for 2,500 people and has over 100 templates
- MailChimp provides a free plan for 250 contacts and 500 emails per month
There is helpful information about how to communicate with people available here on the Threat Aware website. As a reminder, you only need to notify individuals directly if you have determined that there is likely to be a “high risk” to their rights and freedoms.
You may wish to include the following information in your notification:
If you don’t have an email, home address or phone number for the person, it is worth double-checking whether they need to be contacted with regard to the breach.
The National Cyber Security Centre has great guidance on how to create an effective communications strategy here.
It’s also important to think about how you are communicating with people who were not affected by the data breach, such as:
- Your employees
- Trustees or Board members
- Key stakeholders, such as grant-makers, local authorities and delivery partners
It is worth taking time to review any agreements that you have with other stakeholders to see if you are required to notify them.
- ICO helpline: 0303 123 1113
- Charity Commission for England & Wales: 0300 066 9197
- The Scottish Charity Regulator (OSCR): 01382 220446
- Charity Commission for Northern Ireland: 028 3832 0220
The page on our website that provides more details on the data breach has a set of FAQs that will answer any questions that you have. We are committed to being transparent and clear about what has happened.
If you need further information, please collate all the questions that your organisation has and ask your appointed lead contact to email them to incident@beaconcrm.org.
Please be aware that we are expecting a significant amount of contact and have assigned extra resources to answer your questions as quickly as possible; however, we expect this to take longer than usual.