Cyber Incident Victim: Beacon
Timeline
Summary
A cyber incident affecting the third‑party CRM provider Beacon led to unauthorized access to the data of roughly 1500 UK charities, including organizations in healthcare and victim support. The accessed information comprised names, email addresses, telephone numbers, donation records and any attached files, though payment card and bank details were not stored in the system. Beacon stated that the data, while encrypted, may have been decrypted by the attacker and that a compromised access key was used to gain entry, with the incident now contained after external cybersecurity assistance.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 4, 2026, Beacon publicly disclosed a cyber incident affecting its CRM platform. The disclosure stated that a compromised access key had been used to gain unauthorized access to Beacon's systems. Beacon did not provide details on how the key was obtained. The company observed a spike in activity during the incident that is symptomatic of data leaving its systems. Beacon noted that the stored data was encrypted but that the unauthorized actor might have been able to decrypt it. Beacon notified all of its customers about the incident on August 6, 2026. Around 1,500 UK charities that use Beacon's CRM were potentially affected. Specific charities that have confirmed their data was accessed include Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice, the Clock Tower Sanctuary, and Victim Support. The incident was first reported in the media on August 7, 2026. Beacon advised its customers to assume that all data stored in the platform, including attachments, had been downloaded.

The types of data believed to have been compromised include names, email addresses, telephone numbers, donation records, and any attached files. Beacon explicitly stated that the compromised CRM system does not hold sensitive patient information, payment card details, or bank account information. Despite the lack of payment data, Beacon told customers they could continue to collect payments via Beacon forms. However, they must follow the steps in the Security Incident Response Guide to update their payment providers and apps. Affected charities have been instructed to report the breach to the United Kingdom’s Information Commissioner’s Office. Beacon said that, after containing the initial incident with the help of external cybersecurity experts, it has not observed any ongoing unauthorized access to its systems. The company confirmed that its customers continue to access the Beacon platform and services as normal. To date, no data linked to the incident has appeared on the dark web. The cyber‑attack has not been attributed to any specific threat actor, and the objectives of the unauthorized actor remain unclear.
Beacon told its customers that if they were storing data about people in their Beacon account, it is likely to have been downloaded and they need to evaluate whether they must in turn notify those individuals. The company said it has launched an investigation into the full circumstances of the incident with the assistance of external cybersecurity experts. Beacon emphasized that since containing the initial incident, it has not identified or observed any ongoing unauthorized access to its systems. The incident has prompted several charities to publicly confirm that their supporter databases were among those accessed.
