Chiswick House and Upper Room Hit by Beacon CRM Data Breach |
|
Charities warn supporters that personal details have been accessed
August 4, 2026 Two prominent local organisations have confirmed they were caught up in the major data breach affecting Beacon CRM, the Shoreditch-based company whose customer relationship management systems are widely used across the charity and cultural sectors. Chiswick House and Gardens Trust and The Upper Room homeless charity have both contacted supporters to warn that personal information stored at Beacon may have been accessed after an unauthorised individual gained entry to the platform. Beacon CRM disclosed to clients on 3 August that compromised credentials had been used to infiltrate its systems. The company said its current understanding is that copies of database backups were made and were “likely downloaded,” although a forensic investigation with external cyber-security specialists is still under way. While Beacon has Cyber Essentials Plus certification – the highest level of assurance in the UK government’s scheme – the incident has nonetheless affected a wide range of organisations. English National Ballet and some branches of Macmillan are among those reportedly impacted, and the Information Commissioner’s Office has confirmed it has received “a number of reports from impacted organisations.” Both Chiswick House and Gardens Trust and The Upper Room have stressed that no bank account numbers, sort codes, full card numbers or card security details were stored in Beacon, and therefore are not believed to be affected. Payment credentials are held separately. Early indications also suggest that no customer passwords or payment details have been accessed. Even so, both organisations have urged supporters to be cautious of unexpected emails or messages that appear to reference donations, Gift Aid or their relationship with the charity. In its message to supporters, Chiswick House and Gardens Trust explained that names, contact details, donation histories, Gift Aid information, correspondence and uploaded documents may have been stored in the system. The Trust has reported the incident to the Information Commissioner’s Office and the Charity Commission, notified its insurer, required authorised Beacon users to reset passwords, and begun reviewing its own security and data-retention arrangements. It emphasised that there is currently no evidence of misuse, but warned that the information could be used to make phishing attempts appear more convincing. The Upper Room has issued similar guidance, noting that details relating to supporters, donors and volunteers may have been included in the affected records. It too has filed reports with regulators, reset access credentials, reviewed user permissions and asked Beacon for further information as the investigation continues. The charity said it was “very sorry” to share the news and acknowledged the concern it may cause among those who entrust it with personal information. Beacon CRM became aware of the potential cyber attack on 29 July and says it “immediately” engaged external specialists to secure its systems. The company has published a response guide for charities using its platform, advising them to check regulatory requirements and take appropriate steps. Many of Beacon’s clients are cultural organisations, community charities and fundraising bodies that rely on CRM systems to manage supporter relationships.
|