A cyber incident affecting Beacon, a third-party customer relationship management (CRM) provider, has potentially led to data breaches for approximately 1,500 UK charities, including those in the healthcare and victim support sectors. The company publicly disclosed the incident on August 4, 2026, and confirmed it had notified all its customers by August 6.
Beacon stated that an unauthorized actor gained access to its systems using a compromised access key, describing the method as more sophisticated than a simple username and password breach. The company has not provided details on how this key was obtained. Following the breach, Beacon observed a "spike in activity" indicative of data exfiltration from its systems.
The affected data is believed to include names, email addresses, telephone numbers, and donation records. Beacon has advised its customers to assume that all data stored on its platform, including attachments, has been downloaded. While the stored data was encrypted, Beacon indicated that the unauthorized actor might have been able to decrypt it. However, the compromised CRM system does not store sensitive patient information, payment card details, or bank account information.
Several UK-based charities have confirmed their databases were among those accessed. These include Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, and Rowcroft Hospice in the healthcare sector, as well as the homelessness charity Clock Tower Sanctuary and the organization Victim Support.
Beacon has confirmed that the incident has been contained with the assistance of external cybersecurity experts, who are currently investigating the full scope of the breach. The company has not identified any ongoing unauthorized access to its systems since containment, and customers can continue to use the platform and services normally. Beacon also informed customers that they can safely continue to collect payments via Beacon forms but must follow specific steps in a Security Incident Response Guide to update their payment providers and apps. Impacted charities have been instructed to report the breach to the UK’s Information Commissioner’s Office (ICO).
As of now, no specific threat actor has been attributed to the attack, and their objectives or intended use of the compromised data remain unclear. No data linked to this incident has appeared on the dark web. The charitable sector is often considered an attractive target for cyberattacks due to typically minimal security investments, high reliance on third-party platforms, and the significant reputational risks associated with breaches, which can undermine donor trust. Donor databases contain personally identifiable information such as names, addresses, giving history, and Gift Aid declarations, which can be exploited for targeted fraud and social engineering.






