People who donate to, volunteer with or receive support from charities across the UK could have had their personal information caught up in a cyber incident affecting charity software provider Beacon CRM.
Beacon, which provides customer relationship management (CRM) software to more than 1,000 charities, has confirmed that copies of customer database backups were likely accessed by an unauthorised third party after compromised login credentials were used.
Exactly which charities and individuals are affected is still being established. However, some organisations have already started contacting supporters after discovering their data may have been involved.
What happened?
Beacon says it became aware of the incident on 29 July 2026 and launched an investigation with cybersecurity specialists.
According to the company, compromised credentials were used by an unauthorised third party to make copies of database backups containing customer information.
At this stage, Beacon says:
- There is no evidence the copied data has been shared on the dark web or published online
- No ransom demand has been received
- Services have continued to operate normally
- Law enforcement, regulators and cybersecurity experts are investigating.
The Information Commissioner’s Office (ICO) has confirmed it has received reports from affected organisations.
Could your information be affected?
If you have donated to a charity, volunteered, attended fundraising events or received support from an organisation that uses Beacon CRM, your personal information may have been included.
Depending on what each charity stored in Beacon CRM, this could include:
- Your name
- Email address
- Telephone number
- Postal address
- Donation history
- Volunteer records
- Event registrations
- Membership details.
Some charities may also hold more sensitive personal information, depending on the services they provide.
What should you do?
There is no indication that people need to take immediate action, but it is sensible to stay alert while investigations continue.
If you are contacted by a charity about the incident:
- Read the information carefully
- Be cautious of unexpected emails, phone calls or text messages claiming to be from the charity
- Never click suspicious links or provide passwords or banking details
- Contact the charity directly using details from its official website if you are unsure whether a message is genuine.
Even if only contact details were accessed, cybercriminals sometimes use this information to send convincing phishing emails pretending to come from trusted organisations.
Find out how to stay safe following a data breach in our handy guide.
Which charities have confirmed they are affected?
Beacon has not released a full list of affected organisations. However, some charities have already notified supporters.
The English National Ballet has warned customers that email addresses and some business contact details may have been affected.
London homelessness charity Upper Room has also contacted supporters, donors and volunteers whose information may have been involved.
More organisations may contact supporters as they complete their own investigations.
What should charities be doing now?
While the investigation continues, charities using Beacon CRM should be reviewing exactly what information they stored and assessing the potential impact on supporters.
Depending on the circumstances, organisations may need to:
- Assess the risks to individuals
- Report the incident to the ICO
- Notify affected individuals if there is a high risk to their rights and freedoms
- Provide clear guidance on what supporters should do next
- Prepare to answer questions from donors, volunteers and beneficiaries.
Being open and transparent helps supporters understand what has happened and reduces the risk of confusion if they receive suspicious communications.
What happens next matters
Even if the breach occurred at a third-party supplier, charities still have responsibilities under data protection law. That’s because using an external provider does not remove a charity’s responsibility for protecting the personal data it collects or ensuring it is handled appropriately.
So, what happens next matters.
Organisations that respond quickly, communicate openly and meet their legal obligations are better placed to protect supporters and maintain trust.
Furthermore, where charities fail to respond appropriately or meet their legal obligations, they may face regulatory action by the Information Commissioner’s Office or, in some circumstances, compensation claims from affected individuals.
Could compensation claims follow?
Whether someone has a data breach claim depends on several factors, including what personal information was exposed, whether data protection law was breached and whether they suffered financial loss or emotional distress as a result.
The investigation into the Beacon CRM incident is still in its early stages, so it is too soon to know whether legal claims will arise.
As more information becomes available about which charities were affected, what information was involved and whether supporters face any ongoing risks, we’ll continue to provide updates.
Join the Claim connects consumers with SRA-regulated lawyers. Keep an eye out for updates on any potential claim and possible eligibility checks/registration opportunities.