Wednesday, 5 August 2026Est. 2026 · United Kingdom

Associations

News, data & analysis for the people who run UK membership organisations

The Wire

Beacon CRM cyberattack: charities told to assume data was copied

Beacon CRM, the UK charity-sector customer relationship management provider with more than 1,500 customers, has confirmed a cyberattack in which copies of database backups were likely downloaded by an unauthorised third party, and is warning customers to assume that all data they stored on the platform has been copied (The Register, 5 August 2026).

Beacon CRM has suffered a cyberattack in which database backups were likely copied and downloaded by an unauthorised third party. The company is telling its 1,500-plus charity customers to assume all stored data, including attachments, was taken and may be readable. Affected charities, as data controllers, must assess ICO reporting duties within 72 hours, consider Charity Commission serious-incident reports, and communicate with members and donors.

What happened?

Early evidence points to compromised credentials being used to access Beacon’s systems, according to the company’s incident FAQ. One affected charity said Beacon became aware of the attack on 29 July. In its statement, Beacon said its investigation had confirmed “copies of database backups were made and likely downloaded by the unauthorized third-party”, with evidence of “a spike in activity during the incident timeline symptomatic of data leaving our systems”.

The company said it is unlikely to be able to establish exactly what data was taken, and advised that anyone with a paid account or free trial created before 27 July “should assume that all data stored in it was downloaded”. Although the data was encrypted, Beacon warned it is possible the attackers were able to decrypt it. All user passwords have been reset with stronger requirements. The company has not commented on how the attackers got in, nor on whether any extortion demand was made.

Who is affected?

Because Beacon is built specifically for the charity sector, the confirmed list is a roll call of UK charities. The Molly Rose Foundation confirmed that personal data of supporters, donors and service users was affected, including names, addresses, email addresses, phone numbers, dates of birth and donation records. English National Ballet said contact information had been accessed, though no passwords or payment details (BBC News, 4 August 2026). Also confirmed: The Upper Room, Chiswick House and Gardens Trust, Victim Support (which says no victim data was affected), Macmillan Cancer Support Jersey, the young people’s charity Motiv8, and UK-Med. The Scottish Council for Voluntary Organisations noted that many Scottish charities use the platform without naming individual victims.

What must affected organisations do now?

The legal weight lands on the charities, not on Beacon. Each affected organisation is a data controller in its own right, and the duties are its own. The order of operations:

  1. Establish scope. What categories of personal data did you hold in Beacon, on whom, and how sensitive? Donation records and service-user data raise the risk assessment fastest.
  2. Assess the ICO duty. Personal data breaches likely to risk individuals’ rights and freedoms must be reported to the ICO within 72 hours of the organisation becoming aware. Beacon informed customers from 3 August, so the clock is already running for most; document your reasoning either way.
  3. Consider the Charity Commission. A data breach at a supplier can be a serious incident requiring a report to the Commission; trustees should minute the decision and the basis for it.
  4. Communicate with your people. Where the risk to individuals is high, UK GDPR requires direct communication without undue delay. English National Ballet’s notice is the working model: say what happened, what may be affected, what you are doing, and what members and donors should watch for, chiefly unexpected emails and sender verification.
  5. Record everything. The timeline, the assessment, the notifications. If the ICO ever asks, the file is the defence.

Our member data protection briefing covers the DUAA-era duties in normal times; the 72-hour discipline is the same, the stakes are not.

What happens next?

Beacon says its investigation continues and services were not interrupted. For the sector, the larger conversation is supply-chain risk: a CRM is the single largest concentration of personal data most charities hold, and this week has shown what that concentration is worth to an attacker. Procurement teams renewing this year should expect security questions, breach-history questions and notification-speed commitments to feature in every CRM conversation, from the largest platforms to the smallest. Our UK membership software market briefing maps the charity-CRM tier this incident sits in.