Beacon CRM Cyberattack Exposes UK Charity Donor Data
A cyberattack on Beacon CRM has compromised sensitive data belonging to over 1,500 UK charities, including donor and service user information.

Beacon CRM, a platform widely used by UK charities, has confirmed it was the target of a significant cyberattack that resulted in the exposure of sensitive customer data. The breach, discovered around July 29, has prompted Beacon to warn its users to assume that all data stored on the platform, including potentially decryptable encrypted information, was copied and downloaded by unauthorized third parties.
In a statement, Beacon indicated that its investigation confirmed "copies of database backups were made and likely downloaded by the unauthorized third-party." The company also noted "a spike in activity during the incident timeline symptomatic of data leaving our systems." Due to the inability to ascertain the exact nature and scope of the exfiltrated data, Beacon is advising all customers with paid accounts or free trials created before July 27 to assume that all their stored data, including attachments, has been compromised.
While Beacon CRM encrypts customer data, the company has cautioned that the attackers may have been able to decrypt it. This means that sensitive information, such as names, addresses, contact details, donation records, and personal service user information, could now be in the hands of malicious actors. Beacon has not disclosed details regarding the method of intrusion or whether any extortion demands have been made, but early evidence suggests compromised credentials may have been used to gain access.
As a precautionary measure, Beacon has reset all user passwords and implemented stricter requirements for new passwords. Affected charities are urged to conduct their own assessments to understand the full extent of the impact on their operations and constituent data. The incident response is ongoing, with Beacon working to provide further clarity as its investigation progresses.
Several high-profile UK charities have confirmed they were impacted. The Molly Rose Foundation, an advocate for the UK's Online Safety Act, reported being notified by Beacon on August 3rd and confirmed that personal data of its supporters, donors, and service users was affected. Other confirmed victims include the Scottish Council for Voluntary Organisations (SCVO), The Upper Room, Chiswick House and Gardens Trust, Victim Support (though no victim data was affected), Macmillan Cancer Support Jersey, Motiv8, UK-Med, and the English National Ballet.
The attack highlights the vulnerability of specialized software platforms serving critical sectors like charities. The reliance of these organizations on such tools means that a single breach can have far-reaching consequences, impacting not only the organizations themselves but also the individuals they serve and support. The potential for decryption of sensitive data amplifies the risk of identity theft, fraud, and further targeted attacks against individuals whose information was compromised.
Beacon CRM's focus on the charity sector means that the majority of affected entities are UK-based non-profits. This incident underscores the need for robust security measures within the technology providers that underpin the operations of these vital organizations. The ongoing investigation aims to shed more light on the attack vector and the full scope of the data breach, but the immediate advice remains to treat all data as compromised.