Beacon CRM Breach: What UK Charities (and Any Organisation Using a Third-Party CRM) Need to Do Now

Beacon CRM, a customer relationship management platform used by more than 1,500 UK charities, has confirmed a cyber security incident that has exposed supporter and donor data across a growing number of organisations. Victims already known to be affected include the Molly Rose Foundation, Victim Support, and the Scottish Council for Voluntary Organisations.

What happened

Beacon became aware of the incident on 29 July 2026. Compromised login credentials were used by an unauthorised third party to access Beacon’s systems and make copies of database backups. Beacon has said it cannot rule out that this data was downloaded, and is advising customers to assume everything stored on the platform, including attachment files, may have been taken.

Charities were notified on 3 August, five days after Beacon first detected the breach. Affected data varies by organisation but can include names, addresses, email addresses, phone numbers, dates of birth, and donation or payment records. Several charities have already reported the incident to the Information Commissioner’s Office and the Charity Commission.

Why this matters beyond the charity sector

This is a supply-chain breach, not a direct attack on any individual charity’s own systems. It is a reminder that your organisation’s data security is only as strong as every third-party platform you trust with it. If you use a CRM, donor management system, or any cloud platform to store customer or supporter data, this could just as easily be you, regardless of your own internal security posture.

If you use Beacon CRM directly

  • Read Beacon’s own customer guidance first; treat it as the primary source of truth for your specific account.
  • Assume any data stored in Beacon, including attachments, may have been accessed.
  • Report to the ICO if there’s any risk to individuals’ rights and freedoms, and to the Charity Commission if you’re a registered charity.
  • Review your Data Protection Impact Assessment and Record of Processing Activities for any system that holds personal data.
  • Watch for phishing. Even contact-only data (names, emails, phone numbers) is enough for attackers to craft convincing follow-on scams impersonating your organisation.

What every organisation should take from this

  • Know your data processors. Keep an up-to-date register of every third party holding personal or business-critical data on your behalf, and what data they hold.
  • Enforce MFA everywhere. This breach reportedly began with compromised credentials. Multi-factor authentication remains one of the highest-value controls against exactly this kind of access.
  • Review vendor security before you sign up, not after a breach. Ask suppliers about their own security certifications, backup encryption, and incident response commitments.
  • Have an incident response plan that includes suppliers. Know who to contact, what your notification obligations are, and how you’ll communicate with affected customers or supporters if a supplier is breached.
  • Train staff to spot follow-on phishing. Breaches like this are often followed by convincing scam emails referencing real details. Make sure your team knows to verify anything unexpected through a separate, trusted channel.
  • Consider breach monitoring services. Knowing quickly when your organisation’s data appears in a breach or on the dark web shortens your response window significantly.

Get a security review

If you’d like a review of your third-party data processors, your MFA coverage, or your incident response plan, get in touch with our team. We help organisations across Gloucestershire and the South West build resilience against exactly this kind of supply-chain risk.

Get a security review

How System Force IT can help

System Force IT provides fully managed IT support and cyber security for businesses across Gloucestershire and the UK, backed by UKAS ISO/IEC 27001 certification. If you would like help with any of the above, our managed IT support team is here for you. Get in touch or call 01452 701355 for a no-obligation chat.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name