Update: 12 August 2026
Beacon has provided a significant update to its investigation since this article was originally published.
Beacon now says its assessment is that the threat actor exported all data contained within the Beacon database. This follows analysis showing a significant increase in data transfer on 27 and 28 July 2026, which Beacon says correlates with the malicious activity.
Beacon has also provided further information about the likely cause of the incident. Its current understanding is that a compromised Amazon Web Services (AWS) access key was used to gain access, potentially after being exposed within public JavaScript build artefacts in the Beacon application. Beacon describes this as more sophisticated than a compromised username and password.
Although the data was encrypted at rest within AWS, Beacon says the threat actor had valid credentials. As a result, downloads made using those credentials would have been decrypted by AWS and available to the threat actor in an unencrypted form.
Beacon has confirmed that its platform remains operational and says there is no evidence that card details were compromised.
Following identification of the probable cause, Beacon says it has remediated the vulnerability, reset credentials for services and accounts integrated with AWS, and introduced additional security monitoring. Beacon also says its external cyber security specialists have not identified or observed any ongoing unauthorised access since the initial incident was contained.
What should charities do now?
This update makes it even more important that charities using Beacon do not assume their data was unaffected.
Beacon is recommending that customers continue their analysis to understand what information they held within the platform and determine whether they need to notify affected individuals or relevant regulators.
Charities should continue to follow Beacon’s Security Incident Response Guide, including reviewing the data held within their account, considering their obligations as Data Controller, assessing whether the incident meets the threshold for reporting to the ICO and determining whether individuals need to be informed. Registered charities should also consider whether the incident meets the threshold for reporting to their relevant charity regulator. Beacon’s response guide provides further information on these steps.
What does this mean for charity marketing and communications teams?
For marketing and communications teams, this isn’t simply an IT or data protection issue.
CRM data often sits at the centre of a charity’s relationship with its supporters. It may contain information relating to donors, volunteers, event participants, mailing preferences and other people who have interacted with the organisation.
If your charity determines that individuals need to be contacted, how that communication is handled matters.
Communications should be clear, factual and coordinated with whoever is leading your organisation’s incident response. Supporters should understand what has happened, what information may have been affected, what your charity is doing in response and whether there is anything they need to do.
Marketing teams should also consider planned activity.
If fundraising appeals, supporter emails or other campaigns are scheduled for audiences potentially affected by the incident, it is worth reviewing whether the timing and messaging remain appropriate. Continuing with scheduled communications without considering the wider context could risk undermining supporter trust.
There is a broader lesson here too.
A CRM isn’t simply a database sitting behind your fundraising or marketing activity. It forms part of the infrastructure supporting donor stewardship, email marketing, fundraising campaigns, volunteer communications and the wider supporter experience.
Incidents like this demonstrate why marketing, fundraising, technology and data governance increasingly need to work together.
At Blake Mark Productions, we don’t provide cyber security or legal advice. As a charity marketing agency, our role is supporting the marketing and communications considerations surrounding situations like this, including supporter communications, email marketing, website updates, campaign planning and wider digital strategy.
Where an incident affects planned marketing or supporter communications, we can work alongside internal teams and specialist advisers to help ensure activity remains clear, appropriate and aligned with the organisation’s wider strategy.
Update: 3rd August
If your charity uses Beacon CRM, you’ve probably seen the recent communications regarding the security incident.
News of a cyber security incident involving one of your suppliers can understandably raise questions, particularly when that supplier stores supporter, donor or volunteer information on your behalf.
While Beacon continues its investigation with external cyber security specialists, it has already provided detailed guidance to help customers understand their responsibilities and the practical steps they should now consider taking.
Rather than relying on speculation or commentary shared online, this article explains the current position, highlights the official guidance available from Beacon and outlines the practical actions charities should now be considering.
What has happened?
Beacon has confirmed that it recently experienced a cyber security incident in which an unauthorised third party gained access to its systems using compromised credentials.
According to Beacon’s latest update, copies of database backups were created and, while exfiltration has not been conclusively confirmed, the evidence currently available suggests those copies were likely downloaded. Beacon has engaged external cyber security specialists, implemented containment measures and confirmed that the platform remains fully operational.
At the time of writing, Beacon’s investigation remains ongoing and further updates may be published.
For the latest information, charities should refer directly to Beacon’s official resources:
Start by following Beacon’s guidance
Every charity’s use of Beacon is different.
Some organisations use it purely for fundraising, while others manage volunteers, events, memberships, Gift Aid, service users or wider supporter relationships.
Because of this, there isn’t a single response that’s appropriate for every charity.
Beacon has published a structured response guide that recommends organisations appoint a lead contact, review relevant internal policies, update Beacon applications and API integrations, consider regulatory obligations and assess whether individuals may need to be informed.
Working methodically through that guidance is the best starting point before making any wider decisions.
Review your internal policies
Incidents involving third-party suppliers are exactly why organisations have governance policies.
Beacon recommends reviewing documentation such as your Data Breach and Incident Response Policy, Data Protection and GDPR Policy, Business Continuity Plan, Third-Party Supplier Risk Management Policy and IT Acceptable Use Policy.
Even if these documents haven’t been needed for some time, now is the appropriate moment to ensure they’re being followed consistently.
Consider your GDPR responsibilities
One of the most important parts of Beacon’s guidance relates to data protection.
As the organisation using Beacon, your charity remains the Data Controller for the information stored within the platform. That means your organisation must assess whether the incident meets the threshold for reporting to the Information Commissioner’s Office (ICO). Beacon cannot make that decision on your behalf.
The ICO provides detailed guidance to help organisations determine whether a personal data breach needs to be reported and what information should be included if a report is required.
Useful resources include:
Registered charities should also consider whether the incident is reportable to the relevant charity regulator, as highlighted within Beacon’s own guidance.
Think about the people behind the data
While it’s natural to focus on systems and compliance, it’s equally important to consider the individuals whose information may have been affected.
Beacon explains that organisations should assess whether there is likely to be a high risk to the rights and freedoms of individuals before deciding whether direct notification is required. The ICO provides further guidance on making this assessment.
If communication with supporters, donors or volunteers does become necessary, it should be timely, factual and transparent.
This is also a good opportunity to review wider security
Although this incident relates specifically to Beacon, it serves as a reminder that every charity depends on multiple third-party platforms.
Your CRM is only one part of your wider digital infrastructure.
You may also rely on your website, online donation platform, email marketing software, cloud storage, payment providers and collaboration tools.
Incidents involving suppliers are uncommon, but they reinforce the importance of reviewing user permissions, enabling multi-factor authentication, maintaining strong passwords and ensuring internal policies remain up to date.
Good cyber resilience isn’t built during an incident. It’s built long before one happens.
Keep monitoring official updates
Cyber security investigations take time.
Beacon has stated that it will continue publishing updates as new information becomes available and encourages customers to monitor its Security Incident Response Guide for the latest advice.
For that reason, charities should avoid relying on rumours or second-hand information and instead continue referring to Beacon’s official communications.
Supporting your charity’s digital infrastructure
Modern charities rely on a growing number of digital platforms to deliver services, engage supporters and manage fundraising activity.
While incidents such as this are thankfully uncommon, they highlight the importance of strong governance, clear internal processes and well-managed digital systems.
At Blake Mark Productions, we support charities with their wider digital infrastructure, from charity website design and WordPress Care Plans to digital marketing strategy and ongoing technical support. Although we don’t provide cyber security consultancy, we understand how closely these systems work together and the importance of maintaining a secure, resilient digital environment.
If you’d like to discuss your charity’s website or wider digital strategy, you can book a free discovery call below.
