Beacon CRM data breach: what charities need to do

21 August 2026 / Insight posted in Articles

The recent cyber security incident affecting Beacon CRM, a customer relationship management platform used by more than 1,000 UK charities and nonprofit organisations, has resulted in the unauthorised access and likely extraction of data held within the platform. Beacon has advised affected organisations to assume that all data stored within the system may have been extracted, including supporter, donor, volunteer and beneficiary information.

While there is currently no evidence that the stolen data has been published or misused, the incident has raised significant concerns across the sector, particularly for organisations holding sensitive personal information relating to service users, donors and vulnerable individuals.

Recommended actions

Our recommendation is to take a proportionate but proactive approach. Organisations should work with Beacon to understand the specific categories of data affected, assess the potential risks to individuals and determine whether the incident meets the threshold for reporting to the Information Commissioner’s Office (ICO) or the Charity Commission.

Charities using Beacon should:

  • work with Beacon to understand what information may have been compromised;
  • assess the potential impact on affected individuals;
  • consider whether regulatory reporting obligations have been triggered; and
  • review communications with supporters, donors, beneficiaries and other stakeholders.

Charities should also review cyber security controls, supplier assurance processes and incident response arrangements to identify opportunities to strengthen resilience and reduce future risk.

Where there is a risk of harm arising from the breach, organisations should communicate openly with affected stakeholders and advise them to remain vigilant for phishing emails, suspicious telephone calls and other social engineering attempts.

Your responsibilities

Trustees and senior leaders remain responsible for ensuring that their organisation meets its data protection and governance obligations. This includes assessing whether the breach constitutes a reportable personal data breach under UK GDPR, notifying the Information Commissioner’s Office (ICO) where required, informing affected individuals where there is a high risk to their rights and freedoms, and considering whether a Serious Incident Report should be submitted to the Charity Commission.

Boards should maintain oversight of the response, ensure that appropriate records of decisions and actions are retained, and demonstrate that they are taking reasonable steps to protect the charity, its beneficiaries and its reputation.

While there is currently no evidence that the data has been misused, charities should treat this incident seriously. A timely and proportionate response will help support affected individuals, demonstrate compliance with regulatory obligations and strengthen resilience against future cyber security threats.

Moore Kingston Smith’s Risk Advisory team are available to help charities assess their exposure, understand their regulatory obligations and respond appropriately to the Beacon CRM incident. If you have concerns about the impact on your organisation or need support determining the appropriate next steps, please get in touch.

Get in touch

How did you hear about us?

reCAPTCHA