Geo Focus: The United Kingdom,
Geo-Specific,
Incident & Breach Response
Confirmed Victims of the Data Breach Include English National Ballet

Beacon CRM, a cloud-based customer relationship management software provider, has experienced a significant security breach resulting in the potential theft of customer data. This revelation has sparked concerns among the over 1,000 charities and nonprofit organizations utilizing the platform for critical functions such as online donation collection, membership management, and event ticket sales.
The breach first came to light when Beacon became aware of potential unauthorized access on July 29. An investigation quickly confirmed that a security breach had indeed occurred, prompting the company to communicate with its customers. According to Beacon, compromised credentials were utilized to gain access to their systems, leading to database backups being copied by intruders. This situation has raised alarms about the extent of the data that may have been extracted from their systems.
The subsequent update from Beacon indicated a troubling reality: the company might never ascertain the full scope of the data stolen. In an abundance of caution, it recommended that customers assume all data stored within Beacon—attachments included—may have been accessed. This breach affects not just the paying customers but also free-trial users who had accounts prior to July 27 at 3:00 UTC.
Beacon CRM is recognized for its versatile capabilities in managing various types of essential charity data. The platform offers out-of-the-box fundraising features as well as the flexibility to store any required data for the organization’s needs. This includes functionalities for tracking animal adoptions, managing grants, and overseeing memorial bench donations—all integrated into a single database.
Among the organizations impacted by this unfortunate incident is the English National Ballet. They expressed their regret in a communication to supporters, acknowledging the potential exposure of contact information as a result of the breach. While the ballet company assured that no passwords or payment details were compromised, they advised individuals to remain vigilant against unexpected emails and to verify the sender before clicking any links.
Another organization affected is the Center for Sustainable Energy, a charity located in Bristol, England. They communicated to their supporters that personal details of donors could have been exposed, alongside information related to donation amounts and transaction dates. Fortunately, no sensitive financial data such as bank account or payment card details were at risk, meaning attackers wouldn’t be able to facilitate unauthorized payments through that information.
Other confirmed victims include the Chiswick House and Gardens Trust and The Upper Room homeless charity, both of which have promptly notified their supporters about the incident. These notifications underscore the seriousness of the breach and the importance of transparency in addressing the concerns of affected parties.
In response to the breach, Beacon has advised its customers to conduct a thorough security assessment and review any regulatory obligations they may have. A key recommendation includes immediately rotating all credentials for applications integrated with Beacon CRM and resetting passwords for payment and related services. This measure aims to mitigate the impact of the breach, as six commonly connected services—like DotDigital, Enthuse, FundraiseUp, GoCardless, JustGiving, and MuchLoved—have already disabled all integrations, along with associated user accounts.
Furthermore, organizations may be required to notify the Information Commissioner’s Office (ICO) within 72 hours of confirming a breach. They might also need to inform various charity regulators, including the Charity Commission for England and Wales, the Office of the Scottish Charity Regulator, and the Charity Commission for Northern Ireland. The responsibility for compliance in such situations highlights the ongoing risks associated with data privacy and protection.
Nebula Design, an agency supporting charitable institutions in England, pointed out that the loss of attachments raises serious concerns regarding the exposure of sensitive information, requiring organizations to notify authorities promptly. This is particularly alarming as such sensitive data crosses the threshold for notification, underscoring that this situation is not merely a supporter data incident but extends to special category data concerning beneficiaries. The implications of the breach touch on various sensitive issues, emphasizing the need for vigilance and a proactive approach in data management and security practices going forward.

