Beacon CRM cyber attack exposes charity sector to major data risk
A cyber security incident at Beacon CRM has left charities across the UK assessing whether personal information belonging to donors, supporters, volunteers and service users may have been copied by an unauthorised third party.
Beacon is a cloud-based customer relationship management platform built specifically for charities. It is used to manage information such as donations, Gift Aid, memberships, supporter communications, volunteers and fundraising activity.
The company says more than 1,000 charities use its platform. In the days following the incident, charities across England, Wales and Northern Ireland began publishing statements warning supporters that information held in their Beacon accounts may have been affected.
The Charity Commission for England and Wales has described the incident as significant enough to expect a large number of serious incident reports from affected organisations. It is also liaising with the Information Commissioner’s Office.
The regulator published specific guidance for charities affected by the Beacon incident on 7 August.
What happened at Beacon CRM?
According to notices published by affected organisations, Beacon identified unauthorised access to its systems and subsequently warned customers that copies of database backups were likely to have been downloaded.
Volunteer Centre Dorset said it was notified by Beacon on 3 August and was told that compromised credentials had been used to gain access to the provider’s systems.
It said Beacon’s investigation indicated that copies of some database backups were likely downloaded.
At the time of its statement, there was no evidence that the stolen information had been published online or misused.
The organisation stressed that it had not been individually targeted. The incident occurred at its CRM provider rather than through an attack directly against Volunteer Centre Dorset.
This distinction matters.
Cloud services allow charities to outsource much of the technical infrastructure needed to run fundraising and supporter databases. But when a supplier serving hundreds or thousands of organisations is compromised, one security incident can affect a significant part of the sector at once.
What information could be involved?
There is no single answer because charities use Beacon differently.
A fundraising charity might hold names, addresses, email addresses, telephone numbers, donation records and Gift Aid information.
A membership organisation could also store membership history, event attendance and communications.
Other charities may use their CRM for volunteer management, referrals or information relating to people who use their services.
That means the severity of the breach is likely to differ considerably between organisations.
Several affected charities have published their own assessments.
Volunteer Centre Dorset said it was reviewing the information it held and contacting people who had been referred to its services. It also provided scam-awareness advice to those potentially affected.
This matters because personal information does not need to include bank details to create risk.
A combination of a person’s name, contact details and relationship with a particular charity could be enough to make a phishing email or fraudulent phone call considerably more convincing.
A criminal who knows that somebody donates regularly to a hospice, disability organisation or refugee charity could potentially use that information to impersonate the organisation.
Some charities hold much more sensitive information than others
The potential impact becomes more serious where a charity works with vulnerable people.
Organisations dealing with mental health, domestic abuse, disability, immigration, poverty or sexual violence can hold information that individuals would reasonably expect to remain highly confidential.
Some affected charities have been able to reassure service users that their most sensitive records were not stored in Beacon.
The Survivors Trust, for example, has said Beacon was used for areas including fundraising, training and membership but was not used to store information about people accessing its sexual violence support services.
That separation of data significantly reduces the possible harm to beneficiaries.
It also illustrates an important principle for other charities.
Not every piece of organisational information needs to sit inside the same CRM.
Separating highly sensitive beneficiary information from fundraising and supporter databases can limit the damage if one system is compromised.
The breach is already costing charities time and resources
The impact is not limited to data protection paperwork.
Affected organisations are having to review databases, assess what information may have been exposed, contact regulators, respond to supporters and consider whether additional security measures are needed.
For smaller organisations, that can mean pulling staff away from frontline work.
The Survivors Trust said the incident had diverted “vital time and resources” from supporting survivors at a time when demand for its services was high and funding was already under pressure.
That is an important part of the story.
A cyber attack on a supplier may begin as a technical problem, but the consequences are operational. Every hour spent investigating records, answering questions or preparing regulatory reports is time that cannot be spent delivering services.
For charities already working with small teams and limited budgets, that pressure can be significant.
The regulatory response
The Charity Commission said it became aware of the incident because of the number of charities potentially affected.
It has asked trustees to consider whether the incident has resulted in, or creates a risk of, significant harm to their charity, beneficiaries, assets, services or reputation.
Where that threshold is met, trustees should consider making a serious incident report.
The regulator has warned that the expected volume of reports may mean responses take longer than normal.
Trustees must also consider their obligations under data protection law.
The Information Commissioner’s Office says organisations do not need to report every personal data breach. Reporting is required where the breach is likely to create a risk to people’s rights and freedoms.
Individuals may also need to be informed directly if the breach is likely to result in a high risk of harm.
The Charity Commission has specifically told affected organisations to consider whether they need to notify the ICO and whether people whose information was held in Beacon should be contacted.
It has also made clear that communication with supporters matters just as much as regulatory compliance.
“Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work,” the Commission said in its guidance to affected organisations.
That point is particularly important for charities.
Donors and service users may never have heard of Beacon CRM. Their relationship is with the charity itself, and they are likely to expect that organisation to explain what happened, what information may have been involved and what they should do next.
Northern Ireland charities have received similar advice.
The Charity Commission for Northern Ireland has urged Beacon users to assess the impact of the incident, document the actions they take and consider whether a serious incident report is required.
Charities are already contacting supporters
A growing number of organisations have published notices explaining how they are responding.
Some have reported the incident to both the ICO and Charity Commission.
Others have contacted supporters, volunteers or service users directly.
Volunteer Centre Dorset said it had activated its incident procedures, reviewed the data it held, notified regulators and introduced additional security measures.
It also said it was contacting people referred to its services by email, letter or telephone, depending on the information available.
Other organisations have published detailed FAQs explaining what types of information they store and whether payment details or sensitive service-user records were held elsewhere.
That level of detail is likely to be important if charities want to maintain confidence.
A generic statement that a supplier has suffered a cyber attack may not be enough for someone who wants to know whether their name, address, donation history or other personal information was involved.
Why this incident matters beyond Beacon
Beacon markets itself as a CRM designed specifically for charities and says more than 1,000 organisations use the platform.
Its popularity reflects a wider change in how charities operate.
Cloud systems have made sophisticated fundraising and data management tools available to organisations that could never afford to build their own technology infrastructure.
A small charity can now automate Gift Aid, track donors, manage memberships, integrate website forms and produce reports without maintaining its own servers.
That brings obvious benefits.
It also concentrates risk.
If a single cloud provider is breached, the attacker may gain access to information belonging to many organisations at once.
The Beacon incident demonstrates why supplier security should be treated as part of charity governance rather than simply an IT purchasing decision.
What trustees should ask about their CRM
Trustees do not need to become cyber security specialists.
They do need to understand where their charity’s information is stored and what could happen if a supplier is compromised.
A board should be able to answer some basic questions.
What personal information is stored in the CRM?
Does the charity actually need to retain all of it?
Are particularly sensitive records stored separately?
Who inside the organisation can access the system?
Is two-factor authentication enforced?
How are former staff accounts removed?
What happens to data backups?
Which subcontractors or third-party services can access the data?
How quickly would the supplier notify the charity following an incident?
Does the charity have a usable copy of its data if the provider becomes unavailable?
Has the supplier been asked for evidence of its security controls?
These are not questions that should be asked only after a breach.
They should form part of routine oversight of any supplier handling important charity data.
Data minimisation suddenly becomes very practical
One of the simplest questions charities can ask following this breach is whether they are storing more information than they need.
CRM databases often grow over many years.
Records can include former donors, old volunteers, historic event attendees, abandoned enquiries and people who have not interacted with the organisation for a long time.
Attachments can remain stored because nobody has reviewed whether they are still necessary.
In normal circumstances, this can look like a housekeeping issue.
During a breach, every additional record becomes another potentially affected person.
Reducing unnecessary data is therefore not just about regulatory compliance. It reduces the scale of damage if a system is compromised.
Trustees should be asking whether their organisation has a clear retention policy and whether it is actually being followed.
The risk of follow-on scams
There is currently no public evidence that information from the Beacon incident has been published or used fraudulently.
That does not mean charities or supporters should ignore the possibility.
Data breaches can be followed by phishing attempts in which criminals use genuine personal information to make fraudulent communications appear credible.
Supporters should be cautious about unexpected emails or calls claiming to be from a charity and asking them to confirm passwords, bank details or payment information.
They should also be wary of messages creating urgency around donations or claiming that payment information needs to be updated because of the breach.
The ICO advises people affected by a breach to ask the organisation what happened, what information was involved and what steps are being taken to protect them.
Cyber security is now a governance issue
For years, cyber security has often been treated as something delegated to whoever looks after a charity’s computers.
That approach is increasingly difficult to defend.
Charities depend on technology for fundraising, banking, payroll, supporter communications, case management and service delivery.
A serious cyber incident can disrupt operations, consume staff time, create regulatory obligations and damage relationships built with supporters over many years.
The Beacon incident shows how those risks can reach an organisation even when its own systems have not been directly attacked.
Trustees may have outsourced the software, but they have not outsourced responsibility for protecting the charity’s information.
For organisations affected by this incident, the immediate task is to establish what data was held, assess the risk to individuals and communicate clearly with regulators and supporters.
For the rest of the sector, the question is broader.
If the technology company holding your charity’s most valuable information was breached tomorrow, would your board know what was stored there, who needed to be told and what to do next?
Published: 21 August 2026
Updated: 21 August 2026