UK charities count the cost of Beacon CRM cyberattack
Database backups likely stolen, potentially exposing donor, supporter, and service user details
Security
UK charities count the cost of Beacon CRM cyberattack
Database backups likely stolen, potentially exposing donor, supporter, and service user details
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities.
The company, which markets its software to charities and has more than 1,500 customers, said its investigation remains ongoing. However, it appears that a substantial amount of customer data was copied, and Beacon is warning users to assume everything they stored on the platform was downloaded.
"Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorized third-party," it said on Tuesday. "We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems.
"It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded."
Beacon also warned that although customer data is encrypted, "it is possible that the unauthorized third party responsible for this incident was able to decrypt it." Customers should therefore assume the copied information was readable.
Beacon did not answer any of The Register's questions, instead offering a statement that echoed the wording of its public FAQ pages.
It did not comment on whether extortion demands were made, nor how or when the attackers got in.
Beacon's information page says early evidence points to compromised credentials being used to access its systems. One affected charity said the company became aware of the attack on July 29.
Beacon also said anyone with a paid account or free trial created before July 27 should assume that all data stored in it was downloaded.
While the incident response folk do their thing, customers have been urged to investigate how badly they were affected. Beacon also reset every user's password and imposed stronger requirements on replacements.
Charities hit
Because Beacon CRM is a product specifically engineered for the charity sector, the bulk of those confirmed to be affected are UK charities.
Among the higher-profile victims is the Molly Rose Foundation, a persistent campaigner on the UK's Online Safety Act.
It said Beacon informed it of the situation on August 3, five days after the CRM company became aware of the breach.
The foundation confirmed that personal data belonging to supporters, donors, and service users was affected.
That includes names, addresses, email addresses, phone numbers, genders, dates of birth, records of donations or payments made to the foundation, and other information supplied in connection with its services and activities.
The Scottish Council for Voluntary Organisations (SCVO) did not identify individual victims, but said many Scottish charities use Beacon CRM.
Other charities confirmed to be affected include:
PANS PANDAS UK, a children's charity for those with the PANS and PANDAS conditions, said that it was unsure whether its data had been affected, having abandoned Beacon earlier in the year.
English National Ballet told The Register: "As one of Beacon CRM's customers, English National Ballet was informed on 3 August 2026 that an unauthorised third party had gained access to their system.
"English National Ballet has not received confirmation that our data was directly affected, however as a precaution we have informed all contacts as soon as possible that their data could potentially have been accessed. ENB take data privacy extremely seriously. We are doing everything we can to reduce the risk of anything similar happening in the future." ®
Originally published on The Register


