Beacon CRM, a software provider serving more than 1,000 UK charities, confirmed a cyber incident involving unauthorized access to customer database backups, discovered July 29, 2026.

An unauthorized third party used compromised login credentials to copy those backups. The Information Commissioner's Office has received reports from affected organizations.

Individuals who donated to, volunteered with, attended fundraising events for, or received support from charities using Beacon CRM may have had personal information exposed. The specific charities and individuals affected remain under investigation.

Data potentially involved includes names, addresses, phone numbers, email addresses and dates of birth. Some records also contained partially masked payment details. Depending on the services each charity provided, more sensitive personal information may have been stored and accessed.

While Beacon pointed to compromised login credentials, industry experts frequently identify exposed cloud service keys as a common entry point for such incidents. AWS has said that exposed long-term credentials are among the top vectors for threat actors in cloud environments, often found in publicly accessible code or configuration files.

The English National Ballet has begun notifying supporters, warning that email addresses and some business contact details may have been affected. London homelessness charity Upper Room has also contacted donors, volunteers and supporters whose information may have been involved.

Charities bear direct responsibility for protecting personal data under UK data protection law, even when using third-party providers. Contracting with an external vendor does not remove that obligation.

No immediate action is required from individuals, but staying alert is sensible as investigations continue. Cybercriminals sometimes use accessed contact details to send phishing emails that mimic legitimate organizations.

More organizations are expected to notify supporters as they complete their own assessments of the breach's scope. Charities using Beacon CRM must determine precisely what information they stored and assess the potential consequences for their supporters, and may need to review their data protection practices as a result.