Beacon CRM Data Breach Exposes Charity Supporters’ Information
A cybersecurity incident at Beacon CRM, a UK-based customer relationship management provider serving over 1,000 charities, has resulted in unauthorized access to database backups containing customer data. The breach, detected on 29 July, involved attackers using "compromised credentials" to copy sensitive information.
Beacon CRM confirmed the incident in a statement, revealing that while immediate containment measures were taken, the breach did not disrupt its services. The company has notified all affected charity clients, regulators, and law enforcement, though it has not disclosed how many organizations’ data was accessed. There is currently no evidence of the stolen data appearing on the dark web or a ransom demand.
The Information Commissioner’s Office (ICO) has been alerted, with Beacon advising charities to assess whether the breach poses a risk to individuals’ rights and freedoms potentially requiring them to notify their supporters. At least one charity, The Upper Room, has already contacted donors and volunteers to apologize for the exposure.
The incident follows a separate outage at CAF Bank, a subsidiary of the Charities Aid Foundation, which disrupted online banking services from 24 July before being resolved. Investigations into the Beacon CRM breach are ongoing, with cybersecurity experts assisting in determining the full scope of the attack.
Beacon CRM cybersecurity rating report: https://www.rankiteo.com/company/beaconcrm
"id": "BEA1785847278",
"linkid": "beaconcrm",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,000+ charities (exact number '
'undisclosed)',
'industry': 'Non-profit/Charity',
'location': 'UK',
'name': 'Beacon CRM',
'size': 'Serves over 1,000 charities',
'type': 'Customer Relationship Management Provider'},
{'customers_affected': 'Donors and volunteers',
'industry': 'Non-profit',
'location': 'UK',
'name': 'The Upper Room',
'type': 'Charity'}],
'attack_vector': 'Compromised credentials',
'customer_advisories': 'The Upper Room contacted donors and volunteers to '
'apologize for the exposure',
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': "High (potential risk to individuals' "
'rights and freedoms)',
'type_of_data_compromised': 'Customer data, personally '
'identifiable information'},
'date_detected': '2024-07-29',
'description': 'A cybersecurity incident at Beacon CRM, a UK-based customer '
'relationship management provider serving over 1,000 '
'charities, has resulted in unauthorized access to database '
'backups containing customer data. Attackers used compromised '
'credentials to copy sensitive information.',
'impact': {'data_compromised': 'Customer data from database backups',
'identity_theft_risk': "Potential risk to individuals' rights and "
'freedoms',
'operational_impact': 'No disruption to services',
'systems_affected': 'Beacon CRM database backups'},
'initial_access_broker': {'data_sold_on_dark_web': 'No evidence'},
'investigation_status': 'Ongoing',
'references': [{'source': 'Beacon CRM Statement'}],
'regulatory_compliance': {'regulatory_notifications': ['Information '
'Commissioner’s Office '
'(ICO)']},
'response': {'communication_strategy': 'Notified affected charity clients, '
'regulators, and law enforcement',
'containment_measures': 'Immediate containment measures taken',
'incident_response_plan_activated': True,
'law_enforcement_notified': True,
'third_party_assistance': 'Cybersecurity experts'},
'stakeholder_advisories': "Charities advised to assess risk to individuals' "
'rights and freedoms',
'title': 'Beacon CRM Data Breach Exposes Charity Supporters’ Information',
'type': 'Data Breach'}