UK charities count the cost of Beacon CRM cyberattack
Beacon CRM, a customer relationship management platform used by more than 1,500 UK charities, has confirmed it was hit by a cyberattack in which copies of database backups were likely stolen. The company has told customers to assume that all data stored on the platform, including attachment files, was downloaded, and that although the data was encrypted, attackers may have been able to decrypt it. This matters because Beacon is used specifically by charities, meaning the exposed data could include sensitive details about donors, supporters and vulnerable service users across the sector.
Beacon said it became aware of the breach on 29 July, with early evidence pointing to compromised credentials as the point of entry, though it has not disclosed how or when attackers got in or whether extortion demands were made. Confirmed victims include the Molly Rose Foundation, whose affected data covers names, addresses, emails, phone numbers, genders, dates of birth and donation records, alongside charities such as The Upper Room, Chiswick House and Gardens Trust, Macmillan Cancer Support Jersey, Motiv8, UK-Med, PANS PANDAS UK and Victim Support, plus wider warnings from the Scottish Council for Voluntary Organisations. Beacon has reset all user passwords with stronger requirements and urged customers created before 27 July to assume their data was compromised.
- Beacon CRM breach may have exposed data from 1,500+ UK charities
- Attackers likely stole and could decrypt database backups
- Molly Rose Foundation and other charities confirm donor/supporter data affected