If you have donated to a charity, volunteered, become a member or used a charity’s services, your personal information could potentially be caught up in the Beacon CRM data breach.
The cyber incident, first reported earlier this year, affected Beacon CRM, a software provider used by more than 1,500 charities and voluntary organisations.
We now know that a copy of the database containing customer data, including attachments, was made and was likely downloaded in a readable format. As more charities investigate what they held within Beacon, some have started contacting people whose information may have been involved.
So, how do you know if you are affected – and what should you do next?
What is the Beacon CRM data breach?
Beacon CRM is a customer relationship management platform used by charities and voluntary organisations to manage information about their supporters and other contacts.
Beacon became aware of a cyber incident on 29 July 2026. Its investigation found that an unauthorised third party had gained access using compromised credentials.
A copy of the database containing customer data was made and Beacon subsequently said the evidence suggested it was likely downloaded in a readable format.
How do I know if I am affected by the Beacon data breach?
You may find out you are affected if a charity contacts you about the breach.
However, investigations are still ongoing, so some people may be affected without knowing yet.
If you know a charity you have dealt with uses Beacon CRM, you can contact it directly to ask whether your information may have been involved.
Which charities have been affected by the Beacon breach?
Organisations that have issued statements or notifications in connection with the incident include George House Trust, the Molly Rose Foundation, Scottish Refugee Council, Bristol Mind, English National Ballet and Robert Burns Ellisland Trust.
Other charities have also contacted their supporters, donors, members and service users.
This is not necessarily a complete list. If your charity isn’t named, that doesn’t automatically mean its information was unaffected.
What personal information could have been exposed?
This will depend on what each organisation stored within Beacon. Information potentially involved across different organisations includes:
- Names
- Home addresses
- Email addresses
- Telephone numbers
- Dates of birth
- Donation and payment records
- Membership information
- Information about people’s interactions with charities.
In some cases, considerably more sensitive information may have been stored.
For example, Manchester-based HIV charity George House Trust has told people using its services that sensitive and personal health information may have been involved, including notes and records relating to their engagement with the charity.
Were bank or card details stolen?
This will depend on the organisation and the information it held in Beacon.
Some affected charities have confirmed that payment card details were not stored within the system. However, other financial information, such as records of donations or payments, may have been stored.
If you receive a notification from an affected organisation, check it carefully to see exactly what types of information it believes may have been involved.
Has the information been published online?
At the time of writing, there is no evidence that the information taken in the breach has been publicly released or misused. However, that doesn’t mean people should ignore the potential risks.
Personal information can be valuable to criminals because it can help them make scams and phishing attempts appear more convincing.
What should I do if my information was affected?
Start by reading any notification you receive from the affected charity. It should explain what information may have been involved and whether there are particular steps you should take.
You should also stay alert for unexpected emails, calls and text messages, particularly if they appear to come from an organisation you have previously supported or used.
Don’t click unexpected links or attachments, and never give someone passwords, verification codes or financial information because they have contacted you unexpectedly.
If you’re unsure whether a message is genuine, contact the organisation separately using the details on its official website.
Find out how to stay safe following a data breach in our handy guide.
Can I ask a charity what information it holds about me?
Yes. Data protection law gives you the right to ask an organisation whether it is using or storing your personal information and to request a copy of that information. This is commonly known as making a subject access request (SAR).
If you are concerned about the Beacon breach, you can also contact the charity directly to ask what it currently knows about the incident and whether your information may have been involved.
Can I claim compensation following the Beacon data breach?
Being affected by a data breach does not automatically mean you are entitled to compensation.
Whether you could have a claim will depend on your individual circumstances.
Relevant factors may include what happened to your information, whether data protection law was breached and whether you suffered financial loss or distress as a result. The Beacon investigation is continuing, so the full impact of the incident is not yet known.
Affected charities are continuing to assess what information they held in Beacon and what the breach means for their supporters, members, volunteers and service users. That means more people could receive notifications as those investigations progress.
At Join the Claim, we’ll continue to follow the Beacon data breach and provide updates as more information becomes available.
Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.