Commission issues guidance for charities after Beacon CRM data breach

07 Aug 2026 News

Kiattisak via Adobe

The Charity Commission has published guidance for organisations affected by a recent data breach at software firm Beacon CRM.

Beacon CRM, which supports more than 1,000 charities, earlier this week reported that “compromised credentials” were used to copy database backups with customer information.

A commission spokesperson confirmed it was in touch with Beacon CRM and the Information Commissioner’s Office (ICO) after many charities reported serious incidents.

In its guidance, published today, the commission states that it has been “actively monitoring the situation” due to the nature of the incident and number of charities affected.

“Due to the volume of such reports expected on this matter alongside other incoming reports, it is likely to take longer than usual for the commission to respond,” it said.

“We appreciate your patience and understanding as we prioritise instances of the greatest risk.

“In the meantime, we would encourage trustees to consult the commission’s guidance for charities on dealing with cyber crime and the ICO’s guidance for organisations.

The commission urged affected charities to communicate clearly with their stakeholders, which it said was “crucial to retaining trust and protecting the relationships that sustain your work”.

“We appreciate the additional resources charities will need to devote to addressing this issue and the commission will seek to ensure its own regulatory engagement with affected charities is proportionate, while seeking to ensure trustees are fulfilling their responsibilities,” it added.

ICO assessing information

Following the cybersecurity incident, Beacon CRM urged its charity customers to consider reporting to the ICO.

In a statement to Civil Society today, the firm said that it was taking the matter “very seriously” and had notified all customers about the breach.

“Since containing the initial incident, we have not identified or observed any ongoing unauthorised access to Beacon’s systems,” a company spokesperson added.

Beacon CRM said that it immediately brought in external cybersecurity experts after learning about the problem and subsequently launched an investigation.

“Our focus is now on supporting them as much as possible in any onward communication of their own regarding potential data impact,” the spokesperson added.

An ICO spokesperson said that it has since received reports from impacted organisations and was assessing the information provided.

“Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms,” the spokesperson said.

"If an organisation has been impacted by this incident, they should use our self-assessment tool.”

Charities contact supporters

The Sheffield Hospitals Charity, Breast Cancer UK and research charity IVAR are among those which have contacted followers after the breach.

Other charities such as the Molly Rose Foundation, the Circle and the Air Cadets Charity have released statements to reassure supporters, donors and service users.

The Molly Rose Foundation said: “We understand that this will be worrying to those affected, and we are truly sorry that this has happened. Protecting your personal information is extremely important to us.

“We are continuing to work with Beacon to establish precisely what information may have been accessed and whether any specific individuals face a heightened risk as a result.”


Editor's note: This article was updated at 15:30 on 7 August 2026 after the Charity Commission published its relevant guidance.

For more news, interviews, opinion and analysis about charities and the voluntary sector, sign up to receive the free Civil Society daily news bulletin here.

More on