TL;DR: Beacon CRM, a customer-relationship-management platform used by more than 1,500 UK charities to track donors, supporters, volunteers, and beneficiaries, told customers on August 3, 2026 that anyone with a paid account or free trial created before July 27 should assume all stored data had been downloaded. The Register reported on August 5 that early evidence points to compromised credentials being used to copy Beacon's database backups [1]. Beacon reset every user's password and imposed stronger replacement requirements, but warned that encrypted data may have been decrypted, leaving charities and the people on their lists to reckon with the possibility that names, addresses, emails, phone numbers, genders, dates of birth, and donation histories are in a criminal's hands [1][2]. The single-vendor cascade touches homeless services, abuse-victim charities, hospice and cancer-support networks, and a national ballet company.

What Happened

Beacon CRM became aware of an intrusion on Wednesday, July 29, 2026, and engaged external cybersecurity specialists the same day [2]. The company began notifying affected customers five days later, on Monday, August 3 [1][3]. The Register broke the news to a wider audience two days after that [1].

Beacon told customers that copies of database backups were made and likely downloaded, and that there is a spike in activity during the incident window "symptomatic of data leaving our systems" [1]. The Register cited evidence pointing to compromised credentials as the initial vector [1]. Beacon told customers they were unlikely ever to learn the exact scope, and recommended assuming every stored field had been taken: "out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded" [1].

Anyone with a paid account or free trial created before July 27 should assume their data was taken, The Register reported, citing Beacon's customer notice [1]. Beacon reset every customer password and added stronger password requirements, but said nothing publicly about how the credentials were obtained or whether any extortion demand had been made [1]. The company declined to answer most of The Register's questions and pointed instead to a public FAQ [1].

What Data Was Taken

The breach covers the standard fields a charity CRM holds for every donor, volunteer, or service user: names, addresses, email addresses, phone numbers, genders, dates of birth, and donation or payment histories [1][2]. Information supplied to charities as part of their services and activities was also part of the dataset [2].

Beacon warned customers that encrypted fields may not have stayed encrypted. "It is possible that the unauthorized third party responsible for this incident was able to decrypt it," the company told customers, without elaborating on which fields or which encryption scheme [1]. If attackers held encryption keys, the breach is functionally a plaintext leak.

For charities that work with people in crisis, the field list is the worry. Names, phone numbers, and addresses for a domestic-violence shelter or a stalking-victim support service turn the donor database into a map. The combination of donation records with identifying information also creates an opening for targeted social-engineering: a phisher who knows you gave twenty pounds to a cancer charity in April is a more convincing phisher than one who does not.

Who Is Affected

The Register named affected organisations including the Molly Rose Foundation, the Scottish Council for Voluntary Organisations (SCVO), The Upper Room, Chiswick House and Gardens Trust, Victim Support, Macmillan Cancer Support Jersey, Motiv8, UK-Med, PANS PANDAS UK, and the English National Ballet [1]. Victim Support, which supports victims of crime, told the public that no victim data was affected and that the records involved supporter and donor data [1]. English National Ballet warned its contacts as a precaution: "English National Ballet has not received confirmation that our data was directly affected, however as a precaution we have informed all contacts as soon as possible that their data could potentially have been accessed" [1].

The Molly Rose Foundation, which works on suicide prevention among young people, told its supporters on August 3 that compromised credentials had been used to copy its Beacon database [2]. The Foundation notified the ICO and the Charity Commission, and said: "We are truly sorry that this has happened... We don't yet have a full picture of the extent of the data breach, but we are working hard with Beacon to establish the facts as quickly as possible" [2]. The Foundation also told supporters to watch for suspicious contact, and not to share passwords, verification codes, or financial details in response to unsolicited requests [2].

Beacon CRM's customer base, more than 1,500 organisations strong, ranges from major national charities to small local services [1]. The Scottish Council for Voluntary Organisations told members the customer set included "donors, supporters, volunteers, and beneficiaries" [3]. SCVO published a step-by-step guide on August 4 urging affected charities to activate their data-breach response, run a risk assessment that accounted for vulnerable individuals, warn staff about phishing attempts, brief trustees, and review supplier-security assurances for other vendors that hold donor data [3]. The Scottish charity regulator (OSCR) has its own notifiable-events process that charities must follow [3].

Why a Single-Vendor Breach Cascades This Far

The breach is a textbook example of a single point of failure. One CRM vendor holds the donor and supporter data of more than 1,500 UK charities, and a credential compromise against that vendor can turn into many downstream breaches at once [1]. Beacon's published trust page, which makes the case for the company's ISO 27001:2022 and Cyber Essentials Plus certifications and its hosting on UK-based AWS and Google infrastructure, frames the breach against those security assurances [4]. The trust page quotes Beacon CTO David Simpson: "Keeping your data secure is the most important thing we do at Beacon" [4].

For donors and supporters, the practical effect is that any number of charities they have given to, volunteered with, or signed up to hear from may now hold the same data in an adversary's hands. The Register reports a "growing list" of charities coming forward to confirm they were affected [1]. The UK has its own data-protection regulator and a free cyber-incident response line (0800 1670 623) in SCVO's guidance for charities [3]. The breach sits alongside the existing pattern covered by State of Surveillance coverage of the Adidas third-party breach and the Canvas LMS student-records breach: one vendor, one credential, many downstream victims.

What to Watch

The credential vector. Beacon and the affected charities have not said publicly whether the compromised credentials belonged to a Beacon employee, a charity admin, or a third-party integration. The Register cited "early evidence" of credential compromise [1]. The answer matters: if it is a Beacon-side compromise, the fix is on Beacon; if it is a customer-side compromise, charities need to review their own access controls.

The "decrypted" claim. Beacon told customers the attackers "may have" been able to decrypt encrypted fields. Whether encryption was actually defeated, and which fields, will determine the severity of any ICO finding and the practical harm to affected individuals.

Phishing campaigns against donors. Affected charities have warned supporters to watch for suspicious contact. Watch for campaigns that use real donation history (date and amount) as a social-engineering hook. A phisher who knows a donor's history can make a more convincing message [1][2].

The "growing list" of named charities. The Register notes the list of charities coming forward to confirm they were affected is still expanding [1]. Watch for further named organisations to issue donor warnings.

Sources

  1. The Register, Connor Jones - UK Charities Count the Cost of Beacon CRM Cyberattack (August 5, 2026). https://www.theregister.com/security/2026/08/05/uk-charities-count-the-cost-of-beacon-crm-cyberattack/5283305
  2. Molly Rose Foundation - Statement: Beacon CRM Data Breach (August 3, 2026). https://mollyrosefoundation.org/molly-rose-foundation-affected-by-beacon-crm-data-breach/
  3. Scottish Council for Voluntary Organisations (SCVO), Alison Brogan - Beacon CRM Cyber Incident: What Scottish Charities Should Do Now (August 4, 2026). https://scvo.scot/p/106392/2026/08/04/beacon-crm-cyber-incident-what-scottish-charities-should-do-now
  4. Beacon CRM - Trust and Data Security. https://www.beaconcrm.org/trust