If you’ve supported or used a charity that uses Beacon CRM, your personal information may have been caught up in a major data breach.
Join the Claim isn’t a law firm. We connect you with regulated UK firms that run group action claims. If one of our partner firms takes this case forward, we’ll share more details, including how to check your eligibility.
Join the Claim Limited is a claims management company. This claim is not regulated by the Financial Conduct Authority. Join the Claim Limited is authorised and regulated by the FCA (FRN: 1053404) for regulated claims management activities only.
Register your interest
Overview
A cyber security incident affecting Beacon CRM may have exposed personal information held by charities and voluntary organisations across the UK.
Beacon provides customer relationship management (CRM) software to more than 1,500 organisations. Its systems hold information about supporters, donors, members, volunteers and people who use charity services.
Beacon has now completed its investigation into the breach. It found that an unauthorised third party gained access on 27 July 2026 and made a copy of its customer database. Beacon cannot confirm exactly what information was taken, but says the amount of data downloaded suggests the entire database may have been copied.
A growing number of charities have contacted people whose information may have been involved. The type of data at risk varies between organisations and may include names, addresses, contact details, dates of birth, donation records and information about people’s interactions with charities.
In some cases, particularly sensitive information may also have been involved.
Beacon says there is currently no evidence that information from the breach has been published or shared online.
Register your interest today and we’ll keep you informed if one of our regulated UK partner law firms is able to investigate potential legal action relating to the incident.
Beacon data breach claim – At a glance
Join the Claim is bringing people together — uniting those who want answers, accountability and stronger data protections from the organisations they trust.
Staying informed is the first step towards change. By registering alongside others affected, you’re showing that people expect better. And that when something goes wrong, they want to see it put right.
How Join the Claim works
Take a moment to answer a few simple questions so we can understand your connection and keep you updated.
Share your details so we can keep you informed if any updates become available.
If a partner law firm takes this claim forward, we’ll let you know the next steps and how to join.
Latest updates on the Beacon CRM data breach
September 2026
Beacon completes its investigation into the cyber security incident. It says an unauthorised third party gained access on 27 July and made a copy of its customer database. Beacon cannot confirm exactly what information was taken, but says the amount of data downloaded suggests the entire database may have been copied. It says there is still no evidence that the information has been published or shared online.
Join the Claim opens registrations for people who want to stay informed about a potential UK claim.
Late August 2026
George House Trust warns people using its services that sensitive and personal health information may have been involved in the breach.
12 August 2026
Beacon provides a further update indicating that a copy of the database containing customer data, including attachment files, had been made and was likely downloaded in a readable format.
Early August 2026
A growing number of organisations begin contacting supporters and service users about the incident.
29 July 2026
Beacon becomes aware of the cyber security incident.
We’ll provide more updates on the data breach as they occur.
Are you affected by the Beacon CRM data breach?
Register your interest today and we’ll let you know if a partner law firm takes this claim forward.
Frequently asked questions about the Beacon CRM data breach
Beacon’s final investigation found that an unauthorised third party gained access to its systems on 27 July 2026.
A copy of its customer database was made. Beacon cannot confirm exactly what information was taken, but says the amount of data downloaded suggests the entire database may have been copied.
Beacon has contained the incident and fixed the security weakness that allowed the unauthorised access.
People whose personal information was stored in Beacon by an affected organisation could potentially be involved. This may include charity supporters, donors, members, volunteers and people who have used charity services.
A growing number of organisations have issued statements or contacted people about the incident. These include George House Trust, Molly Rose Foundation, Scottish Refugee Council, Bristol Mind and Robert Burns Ellisland Trust, among others.
Beacon provides CRM services to more than 1,500 organisations, although this does not mean every organisation or every person whose information was held in Beacon was necessarily affected.
The information involved depends on what each organisation stored in Beacon. Beacon cannot confirm exactly what was taken, but says the amount of data downloaded suggests the entire customer database may have been copied.
Potentially affected information may include names, addresses, email addresses, phone numbers, dates of birth, donation or payment records and details of people’s interactions with charities. Some organisations may also have stored more sensitive information.
Potentially. George House Trust, a charity supporting people living with HIV, has warned that sensitive and personal health information may have been affected.
Health information receives additional protection under UK data protection law because it is classed as special category data.
We are not a law firm. Our role is to keep people informed about potential group actions if one of our regulated UK partner law firms is able to take this claim forward.
By registering, you’ll stay up to date with any developments — from investigations to possible legal action.
No. Registering simply means you’ll receive updates. If a law firm later takes on the case, you’ll be given the option to learn more about the process and any potential costs before deciding whether to take part.
A group action claim allows people affected by the same issue to take action together. This strength in numbers helps stand up to big organisations. Join the Claim helps connect people with law firms so these actions have a real impact.
No. You are free to contact a solicitor directly at any time if you would like legal advice or wish to explore a claim.
When you register your interest with Join the Claim, we’ll keep you updated if one of our regulated partner law firms decides to take the claim forward. However, other law firms may also investigate or pursue claims independently of Join the Claim.
Registering for updates does not prevent you from speaking to another law firm or joining a claim elsewhere.
We connect consumers with their legal dream teams to ensure they get the compensation and support they deserve.
Join the Claim is not a law firm. We connect individuals with top law firms for group or individual claims, and our service is free to use. While we may receive a fee from the law firms we introduce you to, this will not affect your costs or compensation. We are not responsible for the advice or services provided by these firms. Please note, nothing on this website is legal advice, and while we check claim eligibility, we cannot guarantee a law firm will accept a case.
Join the Claim is a trading name of Join the Claim Limited, authorised and regulated by the Financial Conduct Authority (FRN: 1053404). Registered in England and Wales, Company No: 16245278. Registered office: 32 Eyre Street, Sheffield, S1 4QZ.
© Join the Claim All Rights Reserved |