Could you be affected by the Beacon CRM data breach?

If you’ve supported or used a charity that uses Beacon CRM, your personal information may have been caught up in a major data breach. 

Join the Claim isn’t a law firm. We connect you with regulated UK firms that run group action claims. If one of our partner firms takes this case forward, we’ll share more details, including how to check your eligibility. Join the Claim Limited is a claims management company. This claim is not regulated by the Financial Conduct Authority. Join the Claim Limited is authorised and regulated by the FCA (FRN: 1053404) for regulated claims management activities only.

woman in front a computer worried about a data breach

Quick & Simple

Register your interest

Stay Informed

Get justice

Overview

A cyber security incident affecting Beacon CRM may have exposed personal information held by charities and voluntary organisations across the UK.

Beacon provides customer relationship management (CRM) software to more than 1,500 organisations. Its systems hold information about supporters, donors, members, volunteers and people who use charity services. 

Beacon discovered the breach on 29 July 2026. Its investigation later found that compromised credentials were used to gain access, and a copy of customer data, including attachments, was likely downloaded. 

A growing number of charities have since contacted people whose information may have been involved. The type of data at risk varies between organisations and may include names, addresses, contact details, dates of birth, donation records and information about people’s interactions with charities. 

In some cases, particularly sensitive information may also have been involved. 

Register your interest today and we’ll keep you informed if one of our regulated UK partner law firms is able to investigate potential legal action relating to the incident. 

Beacon data breach claim – At a glance  

Status

Stay Informed

UK charities potentially affected

Up to 1,500

Why register with Join the Claim?  

Join the Claim is bringing people together — uniting those who want answers, accountability and stronger data protections from the organisations they trust. 

Staying informed is the first step towards change. By registering alongside others affected, you’re showing that people expect better. And that when something goes wrong, they want to see it put right.  

What do we know about the Beacon data breach?  

  • Beacon provides CRM software to more than 1,500 organisations.
  • Beacon became aware of unauthorised access to its systems on 29 July 2026. The company said compromised credentials were used to gain access. 
  • A copy of the database containing customer data, including attachments, was made and was likely downloaded in a readable format. 
  • Affected information differs depending on what individual organisations stored within Beacon.
  • Potentially affected information may include names, addresses, email addresses, phone numbers, dates of birth and records of donations or payments. In some cases, sensitive information may also have been involved, including information about people’s health or use of charity services.
  • A growing number of charities and voluntary organisations have contacted supporters and service users about the incident. 

How Join the Claim works

Quick survey

Take a moment to answer a few simple questions so we can understand your connection and keep you updated.

Register interest

Share your details so we can keep you informed if any updates become available.

Join a claim

If a partner law firm takes this claim forward, we’ll let you know the next steps and how to join.

Latest updates on the Beacon CRM data breach

  • September 2026

    Join the Claim opens registrations for people who want to stay informed about a potential UK claim. 

  • Late August 2026

    George House Trust warns people using its services that sensitive and personal health information may have been involved in the breach.  

  • 12 August 2026

    Beacon provides a further update indicating that a copy of the database containing customer data, including attachment files, had been made and was likely downloaded in a readable format. 

  • Early August 2026

    A growing number of organisations begin contacting supporters and service users about the incident.  

  • 29 July 2026

    Beacon becomes aware of the cyber security incident.

We’ll provide more updates on the data breach as they occur.   

Join the claim
Join the claim

Are you affected by the Beacon CRM data breach?

Register your interest today and we’ll let you know if a partner law firm takes this claim forward. 

Frequently asked questions about the Beacon CRM data breach

Beacon became aware of unauthorised access to its systems on 29 July 2026.

The company said compromised credentials were used to gain access and copies of customer database backups were made.

Beacon subsequently reported that a copy of the database containing customer data, including attachments, was likely downloaded in a readable format.

People whose personal information was stored in Beacon by an affected organisation could potentially be involved. This may include charity supporters, donors, members, volunteers and people who have used charity services. 

A growing number of organisations have issued statements or contacted people about the incident. These include George House Trust, Molly Rose Foundation, Scottish Refugee Council, Bristol Mind and Robert Burns Ellisland Trust, among others. The full impact of the breach is still being established. 

The information involved will depend on what each organisation stored within Beacon. Potentially affected information may include names, addresses, email addresses, phone numbers, dates of birth, donation or payment records and details of people’s interactions with charities. Some organisations may have stored more sensitive information. 

Potentially. George House Trust, a charity supporting people living with HIV, has warned that sensitive and personal health information may have been affected. Health information receives additional protection under UK data protection law because it is classed as special category data. 

We are not a law firm. Our role is to keep people informed about potential group actions if one of our regulated UK partner law firms is able to take this claim forward.  

By registering, you’ll stay up to date with any developments — from investigations to possible legal action.  

No. Registering simply means you’ll receive updates. If a law firm later takes on the case, you’ll be given the option to learn more about the process and any potential costs before deciding whether to take part. 

A group action claim allows people affected by the same issue to take action together. This strength in numbers helps stand up to big organisations. Join the Claim helps connect people with law firms so these actions have a real impact. 

Rated Excellent


on REVIEWS.io

Rated Excellent on REVIEWS.io

Join the claim
Clifford
Very easy to sign up, hope its sorted soon
Susan
Very easy and quick to complete the claim Everything was explained well and fees payable in etc were made very clear
Peter
So easy to sign up for the claim

Latest Beacon CRM data breach news