UK charities count the cost of Beacon CRM cyberattack

jstanley1 pts0 comments

UK charities count the cost of Beacon CRM cyberattack

Jump to main content

Search

REG AD

Security

UK charities count the cost of Beacon CRM cyberattack

Database backups likely stolen, potentially exposing donor, supporter, and service user details

Connor Jones

Connor<br>Jones

Cybersecurity reporter

Published<br>wed 5 Aug 2026 // 12:04 UTC

Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities.<br>The company, which markets its software to charities and has more than 1,500 customers, said its investigation remains ongoing. However, it appears that a substantial amount of customer data was copied, and Beacon is warning users to assume everything they stored on the platform was downloaded.<br>"Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorized third-party," it said on Tuesday. "We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems.

REG AD

"It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded."

REG AD

Beacon also warned that although customer data is encrypted, "it is possible that the unauthorized third party responsible for this incident was able to decrypt it." Customers should therefore assume the copied information was readable.<br>Beacon did not answer any of The Register's questions, instead offering a statement that echoed the wording of its public FAQ pages.<br>It did not comment on whether extortion demands were made, nor how or when the attackers got in.<br>Beacon's information page says early evidence points to compromised credentials being used to access its systems. One affected charity said the company became aware of the attack on July 29.<br>Beacon also said anyone with a paid account or free trial created before July 27 should assume that all data stored in it was downloaded.<br>While the incident response folk do their thing, customers have been urged to investigate how badly they were affected. Beacon also reset every user's password and imposed stronger requirements on replacements.<br>Charities hit<br>Because Beacon CRM is a product specifically engineered for the charity sector, the bulk of those confirmed to be affected are UK charities.

REG AD

Among the higher-profile victims is the Molly Rose Foundation, a persistent campaigner on the UK's Online Safety Act.<br>It said Beacon informed it of the situation on August 3, five days after the CRM company became aware of the breach.

MORE CONTEXT

Charities remain locked out of CAF Bank online accounts

Payment biz pulls plug on open source charity after KYC spat

Police National Legal Database confirms data theft after dark web leak

UK government investment arm cops to 40-hour leak of officials' contact details

The foundation confirmed that personal data belonging to supporters, donors, and service users was affected.<br>That includes names, addresses, email addresses, phone numbers, genders, dates of birth, records of donations or payments made to the foundation, and other information supplied in connection with its services and activities.<br>The Scottish Council for Voluntary Organisations (SCVO) did not identify individual victims, but said many Scottish charities use Beacon CRM.<br>Other charities confirmed to be affected include:<br>London-based homeless charity The Upper Room

Chiswick House and Gardens Trust

Victim Support (no victim data affected)

Macmillan Cancer Support Jersey, per the Bailiwick Express

Young person's charity Motiv8, according to Portsmouth News

UK-Med

PANS PANDAS UK, a children's charity for those with the PANS and PANDAS conditions, said that it was unsure whether its data had been affected, having abandoned Beacon earlier in the year.

REG AD

English National Ballet told The Register: "As one of Beacon CRM's customers, English National Ballet was informed on 3 August 2026 that an unauthorised third party had gained access to their system.<br>"English National Ballet has not received confirmation that our data was directly affected, however as a precaution we have informed all contacts as soon as possible that their data could potentially have been accessed. ENB take data privacy extremely seriously. We are doing everything we can to reduce the risk of anything similar happening in the future." ®

security

REG AD

AI and ML

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

science

South Korean satellite spots SpaceX lunar impact

Before and after shots of Elon's ejecta snapped by Danuri

devops

Platform Engineering 2.0: your platform was built for a different era. AI just exposed it

PARTNER...

beacon data charities affected said charity

Related Articles