Beacon CRM cyber incident: what charities need to do now

August 7th 2026

Beacon has published an incident guidance page setting out what they believe happened during the recent cyber-attack and a security checklist for Beacon users to work through. It explains how attackers gained access using compromised credentials, what Beacon has done to contain the incident, and the steps organisations should now take inside Beacon and with connected services. Crucially, Beacon advises all customers to assume that all data stored in Beacon – including attachments – has been downloaded.

The incident involved attackers copying database backups. Beacon reports no evidence of misuse but has confirmed that encrypted data may have been decrypted. For many charities, Beacon holds rich supporter profiles, donation histories, volunteer and participant information, event registrations, and narrative attachments. Payment card details are not stored in Beacon.

Beacon’s checklist focuses on securing accounts and integrations. Decisions about risk assessment, ICO reporting, Charity Commission serious incident reporting and notifying individuals still sit with each charity. The steps below explain the actions charities should take to understand the impact and respond appropriately.

Understand what you held in Beacon

Start by mapping the personal data you stored. This includes supporter contact details, donation and membership history, volunteer or participant records, event sign‑ups, email correspondence, and any narrative attachments. Attachments matter. Many organisations store case notes, access requirements, or safeguarding‑adjacent information, and in some cases Gift Aid declarations or direct debit mandates, which carry additional risk if accessed. This understanding underpins every decision that follows.

Assess the risk to individuals

The key question is whether the incident is likely to result in a risk to people. Consider whether the data could enable phishing or social engineering, whether it includes sensitive or potentially harmful information, and whether misuse could cause distress or reputational harm. Make this assessment recordable and proportionate. The ICO expects organisations to be able to explain their reasoning.

Notify the ICO where required

Beacon has advised customers to report the breach to the ICO if personal data was accessed – and for most charities, it was. Under UK GDPR, you must notify the ICO unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Notifications should be made within 72 hours of becoming aware, but late reporting is still better than none. Document your decision‑making either way.

Notify affected individuals

If people’s data is likely to have been accessed and could pose a risk, you must tell them. Keep notifications clear, calm, and honest. Be explicit that payment card data was not involved and offer practical advice on staying alert to phishing or unexpected contact. Transparency maintains trust.

Work through Beacon’s security checklist

Beacon’s incident page includes a Security Incident Response Guide covering password resets, stronger password requirements, multi‑factor authentication, reviewing user accounts and permissions, and updating payment providers and apps connected to Beacon forms. These steps are essential to securing your account and ensuring payment collection can continue safely.

Update governance and documentation

Trustees should ensure the incident and response are properly recorded. Review your Record of Processing Activities (ROPA) and Data Protection Impact Assessment (DPIA) to ensure supplier risk is accurately captured, check contracts and data processing agreements, and follow Charity Commission serious incident reporting guidance. Beacon encourages organisations to revisit internal policies and supplier oversight.

Communicate openly

Clear, proportionate communication with supporters, donors, volunteers, and partners is essential. Stick to confirmed facts, avoid speculation, and keep messaging aligned with your organisation’s tone. The Charity Commission has emphasised that transparency maintains trust.

Strengthen your wider cyber posture

Finally, use this moment to tighten your broader security practices. Review National Cyber Security Centre (NCSC) and Charity Commission cyber guidance, check backup and recovery processes, revisit supplier due diligence, and ensure staff know how to spot suspicious activity. Beacon’s guidance reinforces the importance of strong credentials, MFA, and regular security reviews.

Final Thought

Incidents like this are unsettling, but they’re also a reminder of the responsibility charities carry when they hold people’s data and rely on third‑party systems. Responding well isn’t about panic; it’s about clarity, care, and good governance. A measured, evidence‑based approach will help organisations meet their obligations, support the people whose data they hold and strengthen their resilience for the future.

Get in Touch

If you’re a cultural organisation looking for tailored support, plain English policies, or practical training that empowers your team, we’d love to help. Get in touch for a free 30-minute consultation.

Leave a Reply