← Blog

Beacon CRM Breach: UK Charity Backups Stolen

Share on X

August 5, 2026 reporting / late July incident: UK charity CRM vendor Beacon CRM confirmed that an unauthorized third party accessed its systems, copied database backups, and likely downloaded them. Beacon tells customers with paid accounts or free trials created before July 27, 2026 to assume all stored CRM data and attachments may have left the platform—and may be readable even though backups are encrypted at rest.

The Register’s August 5 write-up and Beacon’s own incident FAQs are the primary sources. BreachHistory indexes the vendor-level incident at beacon-crm-backup2026. Aggregate individual headcount is not yet published.

What happened

Beacon says early evidence points to a compromised access key—more sophisticated than a simple stolen username and password—used to reach its environment. Investigators found activity spikes “symptomatic of data leaving our systems” and confirmed that copies of database backups were made and likely downloaded. The company became aware around July 29, 2026; charity customers began receiving notices in early August.

Containment steps described publicly include remediating the access path, resetting credentials for AWS-integrated services and accounts, forcing user password resets with stronger requirements, and deploying SentinelOne EDR and cloud-native security with 24/7 monitoring. Beacon states it has not observed ongoing unauthorized access to its AWS environment or engineer endpoints since containment, and that the product remained operational.

What data was exposed

Beacon cannot (yet) say which charity tenancies or which tables left in the backup copies. Its guidance is deliberately broad: assume everything you stored in Beacon—including attachment files—may have been downloaded, and assume decryption succeeded.

Individual charity notices already fill in the human stakes. The Molly Rose Foundation said supporter, donor, and service-user personal data was affected, including names, addresses, emails, phones, genders, dates of birth, and donation or payment records. Similar precautionary or confirmed notices have been reported for organizations such as The Upper Room, Chiswick House and Gardens Trust, Macmillan Cancer Support Jersey, Motiv8, UK-Med, and English National Ballet. Victim Support publicly stated that no victim data on its Beacon tenancy was affected—an important reminder that impact can differ by customer even when the vendor backup set is wide.

Beacon says there is no evidence card details were compromised, but still instructs customers to follow its incident-response guide when updating payment providers and connected apps.

Who is at risk

Donors, supporters, volunteers, service users, and staff contacts whose details sat in a Beacon CRM account created before July 27, 2026. Because Beacon markets specifically to charities—with more than 1,500 customers cited in coverage—the blast radius is nonprofit-sector wide rather than a single household brand. Secondary victims include anyone who will now receive convincing “update your Direct Debit / Gift Aid / fundraising appeal” phishing that cites a real charity name and a plausible past donation.

UK charities also face ICO notification duties and trustee governance pressure. Even where a charity cannot yet prove its tenancy was in the stolen backups, Beacon’s abundance-of-caution language pushes many toward contact notification.

Why charity CRM breaches cut deeper

Donor databases mix money, ideology, and often vulnerability. Service-user fields can include safeguarding-adjacent context; campaign lists can reveal political or health-adjacent interests; Gift Aid and payment history help attackers script refund and “failed payment” scams. Unlike a retail coupon dump, charity CRM theft weaponizes trust in the nonprofit sector.

This incident sits alongside other CRM and nonprofit exposures BreachHistory tracks—from large contact-centre CRM failures to smaller donor-platform dumps—but Beacon is notable as a confirmed vendor-side backup theft with explicit “assume everything” guidance to an entire vertical.

What Beacon has not claimed

Beacon has not published a global count of affected individuals, has not named every impacted charity, and has not confirmed whether extortion demands were made. The Register notes Beacon declined detailed press questions beyond its FAQ language. Absence of a ransomware brand name does not make the incident “not a breach”—company confirmation of backup theft is already enough for a verified catalog row.

Likewise, “no evidence card details were compromised” is not the same as “no financial harm.” Attackers with donor histories can still run refund scams, fake emergency appeals, and account-takeover attempts against reused emails and passwords.

Sector pattern: vendor backups vs single-charity incidents

When a single charity is breached, trustees notify their own supporters. When a CRM vendor’s backup set walks, hundreds of charities may need to notify overlapping donor bases on slightly different timelines—creating noise that phishing gangs love. Expect inconsistent email copy, staggered send dates, and lookalike domains registered in the gap between Beacon’s customer notice and each charity’s public statement.

For journalists and researchers, the durable primary sources are Beacon’s FAQ/guidance pages plus named charity statements—not secondary aggregators that collapse every nonprofit notice into a single unverified “millions of donors” headline.

Action items

  1. Charity admins: follow Beacon’s incident guidance, export what you need for your own DPIA, and decide notification scope with counsel/ICO advice—not informal Slack threads.
  2. Reset Beacon passwords to long unique values; treat any shared admin credentials as burned.
  3. Review connected apps and payment providers per Beacon’s guide; rotate API keys and webhooks.
  4. Donors and supporters: expect phishing that cites real charities. Do not click “update payment” links in unexpected emails; use bookmarks or official apps.
  5. Watch for Gift Aid / Direct Debit fraud and unexpected charity SMS that ask for card details.
  6. Enable MFA on personal email and any fundraising portals you use.
  7. Trustees: document the timeline (Beacon awareness July 29; your notice date) for regulator and insurer reporting.

Canonical record

Beacon CRM 2026 on BreachHistory — company-confirmed backup theft; UK charity CRM vendor; individual census pending.

Sources: Beacon incident FAQs, Beacon incident guidance, The Register, UK-Med notice.

Updated 2026-08-06.