Charities’ data likely copied in cybersecurity incident, Beacon CRM warns

04 Aug 2026 News

AKACHA via Adobe

Charities’ data held by a specialist customer relationship management company has likely been downloaded by a third party as part of a cybersecurity incident, it has said.

Beacon CRM, which says it supports more than 1,000 charities, this week reported a breach in which “compromised credentials” were used to make copies of its database backups containing customers’ information.

The company has urged all its charity customers to consider reporting the incident to the Information Commissioner’s Office (ICO).

“A personal data breach should be reported to the ICO unless it is unlikely to result in a risk to the rights and freedoms of individuals,” Beacon said on its website.

“Whether there is a risk will depend on the nature of the data that was stored in Beacon, and so will vary from organisation to organisation.”

It also urged charities to consider contacting their supporters “if there is likely to be a high risk to their rights and freedoms” under data protection law.

London-based homelessness charity the Upper Room has written to its supporters, donors and volunteers to apologise that their information may have been affected, according to the Chiswick Calendar.

In a statement to Civil Society today, a Beacon CRM spokesperson confirmed a cybersecurity incident resulted in “temporary” unauthorised access to its systems.

"We’ve informed all of our customers about this incident as well as the relevant regulators,” they said.

The spokesperson did not confirm how many charities’ data had been accessed.

Incident last Wednesday

Beacon CRM said it became aware of the incident on 29 July and subsequently sought help from cybersecurity experts, with charities told yesterday.

The firm said it is working with law enforcement, regulators and cybersecurity experts to find out what happened.

“Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal,” its spokesperson told Civil Society. 

“There is currently no evidence that this data has been shared on the dark web and there has been no ransom request,” the software company added on its website. 

An ICO spokesperson said: “We are aware of an incident at Beacon CRM and have received a number of reports from impacted organisations. We are assessing the information provided and considering our next steps." 

“Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms.”

Separately, CAF Bank, a subsidiary of the Charities Aid Foundation, today ended an online banking outage which started on 24 July. 

For more news, interviews, opinion and analysis about charities and the voluntary sector, sign up to receive the free Civil Society daily news bulletin here.

More on