Beacon CRM Data Breach: What Should Charities Do?
Beacon is a CRM platform in the UK used by over 1000 charities and non profits. The CRM suffered a data breach in July 2026 with attackers stealing login credentials to gain access to Beacon’s systems and backups. On the 3rd of August 2026, Beacon alerted its customers to the data breach.
What is the Beacon CRM Data Breach?
In July 2026, Beacon CRM suffered a data breach where attackers gained entry from stolen login credentials and accessed internal systems and data such as backups containing contact details and donation histories. Beacon’s customers were alerted to this breach on the 3d of August and currently, there is no evidence to suggest any stolen data has been published publicly.

Is my Charity Affected by the Beacon CRM Breach?
If your charity uses Beacon as its CRM platform, there is a high chance your data may have been affected. The breach has potentially impacted all of Beacon’s current customer base, which is currently over 1000 charities across the UK. If you’re unsure whether your charity may have been affected, we would recommend checking with whoever managed your donor/sponsor database and look for any notifications from Beacon in your emails regarding the breach. Charities such as the British Deaf Association have already confirmed they were affected and have consequently contacted their donors to make them aware.
How do I Find Out if my Charity Uses Beacon CRM?
To find out if your charity uses Beacon CRM, contact whoever manages donor databases within your charity. This may be a CRM manager. If in doubt, contact one of your line managers who will be able to direct your question to the relevant contact.

What Should Charities Using Beacon CRM do Now?
Charities using Beacon CRM should do the following steps straight away:
- Check for a breach notification from Beacon CRM: You should be alerted by Beacon about the breach, if not, get in touch with your CRM manager
- Review and reset credentials: Reset any passwords for Beacon CRM and any integrations you had connected to it.
- Report the breach where required: If your charity is holding personal data, any breach must be reported on the ICO website which can be found here.
- Warn your donors and supporters: Let donors and supporters know of the data breach and that their details may be exposed. This allows them to watch for potential phishing attempts.
- Keep monitoring: Beacon is releasing more information frequently surrounding the data breach. Watch their announcements to understand if you have been affected.
Why do Stolen Credentials Cause Breaches like this?
Stolen credentials cause data breaches like the Beacon CRM breach as it allows the attackers to walk through the front door of a business. It makes being able to stop the entry very difficult as its hard to tell its malicious and not just a standard log in attempt. Once they are inside, they look like any standard user accessing files they normally would access. This is what makes it so hard to mitigate against.

How can Three Cherries help Protect my Business After a Breach like this?
Three Cherries helps businesses in Bristol and the South West reduce exactly these kind of third party risks by reviewing where your data is being held and ensuring any security measures to your businesses are set up and working, minimising the impact a data breach may have on your company.
We also help businesses understand their software supply chain, so if a vendor is compromised, you know right away and have the next steps clearly set out.
If you’re not sure what’s exposed across the tools your business relies on, get in touch and we can walk you through your data setup.
CALL THE IT EXPERTS
SPEAK TO US TODAY
Contact our friendly and knowledgeable team today for IT support in Bristol and the South West.
