A cyber incident at Beacon CRM has left numerous charities grappling with potential data breaches. Find out what's happening and how organizations are responding.

The Charity Commission has acknowledged a significant cyber security incident involving Beacon CRM a platform widely used by charitable organizations. This breach has raised concerns among affected charities and their supporters, prompting a coordinated response from regulatory bodies.
The incident, which came to light in late July 2026, has affected a substantial number of charities, both in the UK and Jersey.
The Information Commissioner’s Office (ICO) and the Jersey Office of the Information Commissioner are closely monitoring the situation, working in tandem with the Charity Commission to mitigate the fallout.
Scope of the Incident
The breach was detected on or around 29 July 2026 when unauthorized access was gained using compromised credentials.
Investigations, supported by external cyber-security experts, revealed that copies of database backups were downloaded. While there is no evidence that the data has appeared on the dark web or that a ransom demand has been made, the potential for misuse remains a concern.
Beacon CRM has advised its customers to assume that data held in their accounts, including attachments, may have been compromised. This precautionary approach underscores the seriousness of the situation and the need for charities to take immediate action.
Affected Charities and Regulatory Response
At least eight charities in Jersey have reported being affected by the breach, including Macmillan Cancer Support JerseyJersey Trees for LifeHealing Waves and the JSPCA Animals’ Shelter. These organizations have been proactive in notifying their supporters and collaborating with regulatory authorities.
The UK Charity Commission has issued guidance encouraging trustees to follow serious incident reporting rules and review cyber-crime guidance. The Commission is also in contact with the ICO, emphasizing the importance of clear communication with stakeholders to retain trust and protect relationships.
Data Involved and Reassurances
The data potentially exposed includes names, postal and email addresses, telephone numbers, donation histories, and Gift Aid status. In some cases, limited additional supporter or volunteer information may also have been compromised. Importantly, bank account and payment card details are not stored in Beacon systems, mitigating the risk of financial fraud.
Affected organizations have emphasized transparency and the absence of evidence of misuse so far. For instance, the JSPCA expressed genuine concern and a commitment to protecting personal information, while Jersey Trees for Life adopted a precautionary approach, acknowledging the early stages of the investigation.
The precise scale of data downloaded and any subsequent misuse remain under investigation. Charities involved have urged supporters to remain vigilant against phishing attempts and to report any suspicious communications. The ICO and the Jersey Office of the Information Commissioner continue to liaise with UK counterparts to ensure a coordinated response.
In the meantime, charities are encouraged to consult the Commission’s guidance on dealing with cyber crime and the ICO’s guidance for organizations. Trustees should also consider their reporting obligations to other regulators and to individuals whose data is stored on Beacon systems.
The Charity Commission will continue to monitor the situation and provide updates as new information becomes available. This incident serves as a stark reminder of the importance of robust cyber security measures and the need for charities to remain vigilant in protecting sensitive data.
