Beacon Data Breach Exposes Personal Information of 1,000+ Organizations, Including JFC Affiliates
On 3 August 2026, Beacon, a third-party database provider storing membership and affiliate data for Justice for Colombia (JFC) and over 1,000 other organizations, reported a cybersecurity incident. An unauthorized third party accessed its systems and exfiltrated copies of database backups before the attack was contained.
The breach exposed sensitive information, including:
- Names, addresses, email addresses, and phone numbers of affiliates and individual supporters
- Affiliated branch/region names and point of contact details
- Records of affiliation fees and donations
Notably, payment card details and bank account information were not stored in the compromised database.
While Beacon has not detected any misuse of the stolen data, JFC has taken steps to mitigate risks, including:
- Reporting the breach to the UK’s Information Commissioner’s Office (ICO)
- Notifying affected affiliates and supporters directly
JFC has also clarified that it will not request payment details or credentials unsolicited and urged vigilance against suspicious communications. The organization has provided a contact email (info@justiceforcolombia.org) for further inquiries.
Source: https://justiceforcolombia.org/justice-for-colombia-beacon-crm-data-breach/
Beacon Data, Inc. cybersecurity rating report: https://www.rankiteo.com/company/beacon-data-inc
Colombian Caravana cybersecurity rating report: https://www.rankiteo.com/company/colombian-caravana
"id": "BEACOL1786105442",
"linkid": "beacon-data-inc, colombian-caravana",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1000+ organizations',
'industry': 'Data Storage/Management',
'name': 'Beacon',
'type': 'Third-party database provider'},
{'customers_affected': 'Affiliates and individual '
'supporters',
'industry': 'Advocacy/Non-profit',
'location': 'UK',
'name': 'Justice for Colombia (JFC)',
'type': 'Non-profit organization'}],
'customer_advisories': 'Direct notifications to affected affiliates and '
'supporters, public advisory on vigilance against '
'suspicious communications',
'data_breach': {'data_exfiltration': 'Yes (copies of database backups '
'exfiltrated)',
'personally_identifiable_information': 'Names, addresses, '
'email addresses, '
'phone numbers',
'sensitivity_of_data': 'High (PII, but no payment/bank '
'details)',
'type_of_data_compromised': 'Personal information, '
'affiliation records, donation '
'records'},
'date_detected': '2026-08-03',
'date_publicly_disclosed': '2026-08-03',
'description': 'Beacon, a third-party database provider storing membership '
'and affiliate data for Justice for Colombia (JFC) and over '
'1,000 other organizations, reported a cybersecurity incident '
'where an unauthorized third party accessed its systems and '
'exfiltrated copies of database backups before the attack was '
'contained. The breach exposed sensitive information, '
'including names, addresses, email addresses, phone numbers, '
'affiliated branch/region names, point of contact details, and '
'records of affiliation fees and donations. Payment card '
'details and bank account information were not stored in the '
'compromised database.',
'impact': {'brand_reputation_impact': 'Potential reputational damage to '
'Beacon and affiliated organizations',
'data_compromised': 'Names, addresses, email addresses, phone '
'numbers, affiliated branch/region names, '
'point of contact details, records of '
'affiliation fees and donations',
'identity_theft_risk': 'High',
'payment_information_risk': 'None (payment card details and bank '
'account information were not exposed)',
'systems_affected': "Beacon's database systems"},
'ransomware': {'data_exfiltration': 'Yes'},
'recommendations': 'Vigilance against suspicious communications, avoid '
'unsolicited requests for payment details or credentials',
'references': [{'source': 'Beacon and Justice for Colombia (JFC) advisories'}],
'regulatory_compliance': {'regulations_violated': 'UK Data Protection Laws '
'(likely GDPR)',
'regulatory_notifications': 'Reported to the UK’s '
'Information '
'Commissioner’s Office '
'(ICO)'},
'response': {'communication_strategy': 'Direct notifications to affected '
'affiliates and supporters, public '
'advisory',
'containment_measures': 'Attack was contained after data '
'exfiltration'},
'stakeholder_advisories': 'JFC has clarified it will not request payment '
'details or credentials unsolicited and provided a '
'contact email (info@justiceforcolombia.org) for '
'inquiries',
'title': 'Beacon Data Breach Exposes Personal Information of 1,000+ '
'Organizations, Including JFC Affiliates',
'type': 'Data Breach'}