Beacon
| Primary URL | Location | Industry | beaconcrm[.]co[.]uk |
Country
United Kingdom
|
Technology
|
|---|
Profile
Beacon functions as a third‑party provider of customer relationship management (CRM) software, with its headquarters located in the United Kingdom. The company’s core product is a CRM platform that enables organisations to record and manage interactions with supporters, volunteers and donors. Within the platform, users can store core contact details such as names, email addresses and telephone numbers alongside a history of donation transactions. In addition to transactional data, the system allows the attachment of ancillary files, including correspondence, reports and multimedia content linked to individual records. Beacon’s service is used by charitable organisations, including those operating in the healthcare and victim support sectors. The platform provides functionalities typical of CRM systems, such as tracking interactions and managing donation records. To safeguard the information held in its databases, Beacon applies encryption to data at rest, although the specific cryptographic protocols employed are not detailed in publicly available sources.
The scale of Beacon’s user base became evident in August 2026 when a security incident exposed the personal and donation data of roughly 1,500 UK charities that relied on its CRM platform. According to Beacon’s disclosure, the compromised information included names, email addresses, telephone numbers, donation histories and any attached files, while payment card numbers and bank account details were not stored in the system. The company stated that, although the data was encrypted at rest, the attacker may have succeeded in decrypting the information after obtaining a valid access key. Investigations indicated that the breach originated from the use of a compromised credential, which allowed unauthorized entry into the CRM environment. Following the detection of the incident, Beacon engaged external cybersecurity specialists to assist with containment, eradication and recovery efforts. The provider confirmed that the intrusion was subsequently contained and that affected clients were notified of the exposure. No public information is available regarding Beacon’s corporate ownership, parent company relationships or subsidiary structure.
