Beacon CRM Data Breach


Update – 13 August 2026

 Beacon has provided a further update following the ongoing investigation by its external cyber security specialists. (Incident)

Beacon’s latest assessment is that a copy of the database containing customer information was made and likely downloaded. While Beacon cannot determine the specific data accessed from its available logs, it is advising customers to assess the information they hold within Beacon as potentially affected.

For Saint Catherine’s Hospice supporters, this means we are continuing to take a precautionary approach and are treating information held within our Beacon account as potentially affected.

Importantly, Beacon has advised that there continues to be no indication that information associated with the incident has been published, disclosed or otherwise misused. Beacon has also confirmed that the incident has been contained and that no ongoing unauthorised access to its systems has been identified.

As previously advised, Saint Catherine’s Hospice does not store bank account or payment-card details within Beacon. Patient and clinical records are held separately and were not affected by this incident.

You do not need to take any immediate action. We continue to recommend that supporters remain alert to unexpected or suspicious communications referring to Saint Catherine’s Hospice or a previous donation.

We will continue to monitor the situation and will update this page if we receive further information that changes our understanding of the incident.

Original Statement

Saint Catherine’s Hospice has been informed of a cyber-security incident affecting Beacon CRM, the supplier that provides the system we use to manage donations and supporter information.

You may already be aware of this cyber security incident involving a key supplier to the charities industry in the UK, Beacon. We are informing our supporters that we are one of the charities that has been affected by the Beacon incident and that if you have donated to, supported or fundraised for Saint Catherine’s in the past seven years, some of your data may have been held within the Beacon platform.

At this time, there is some uncertainty as to the impact on your data. Beacon published a statement on their website which has been periodically updated at Incident.

At the time we were informed, Beacon were using phrases like “we may have experienced a cyber-security incident” and that exfiltration of data “hasn’t yet been confirmed”. Although Beacon said that “the evidence we have so far suggests these copies were likely downloaded”, it was not clear how that specifically related to the data held in our instance on Beacon or what it could mean for the data. Beacon say that the data hasn’t been shared on the dark web. We are awaiting further information and clarity from Beacon.

In the meantime, we can confirm that the type of data held in our Beacon platform would typically include:

• Names,
• Addresses,
• Email addresses,
• Telephone numbers,
• Information about donations or fundraising, including amounts donated

Not every supporter record will contain all of this information.

We are waiting for more information from Beacon as to the details of how the data may have been impacted.

We can say that information such as bank account details, financial details and passwords etc were not included on Beacon and therefore not affected by this incident.

We are mindful that we are passing on uncertainty rather than clarity. We considered whether to wait until we had further information and clarity from Beacon. However, as some other charities had sent out similar communications, we felt it was right that we should do the same. We have also informed the Information Commissioners Office (ICO) and Charities Commission.

We know that there are many charities who have been affected and who have decided not to send out a communication. We recognise it is a careful balance and each charities’ position will be different.

If you have any questions in relation to the incident, please contact:

beaconincident@saintcatherines.org.uk.

Using this dedicated address will help us record and answer enquiries consistently while allowing our other hospice services to continue operating as usual.

We will respond as soon as reasonably possible and appreciate your patience.

We will continue to assess the situation and issue further updates and communications in line with our regulatory responsibilities.

Below are some key points and frequently asked questions that may be helpful.


Beacon CRM cyber-security incident: frequently asked questions

What has happened?

Beacon CRM, the external system Saint Catherine’s Hospice uses to manage supporter, fundraising and donation information, has experienced a cyber-security incident. Based on information so far it appears copies of database backups were made and were likely downloaded.

This was a wider incident affecting organisations that use Beacon and was not limited to Saint Catherine’s Hospice.

Has my information been affected?

if you have donated to, supported or fundraised for Saint Catherine’s in the past seven years there is a likelihood some of your details are held within our Beacon account.

Beacon has said that it may not be possible to establish exactly which records were downloaded. We are therefore taking a precautionary approach and treating information held within our Beacon account as potentially affected.

What information may have been affected?

The information may include:

  • Names
  • Postal address
  • Email address
  • Telephone number
  • Information about donations or fundraising, including amounts donated
Have my bank or payment-card details been affected?

No. Saint Catherine’s Hospice does not store payment-card details or bank account information within Beacon, so these details were not involved in the incident.

Have patient or clinical records been affected?

No. Patient and clinical records are held separately from Beacon and were not affected by this incident.

Has Saint Catherine’s Hospice been hacked?

No. The incident occurred within Beacon’s systems and affected organisations that use its service. It did not involve Saint Catherine’s Hospice patient or clinical systems.

Has my information been misused?

We have not received any evidence that Saint Catherine’s Hospice supporter information has been misused.

However, personal contact and donation information could potentially be used to make a fraudulent email, telephone call or messages appear more convincing. We are therefore asking supporters to remain vigilant to any suspicious contacts they may receive in relation to us.

What should I do?

You do not need to take any immediate action, but please:

  • Be cautious about unexpected communications referring to Saint Catherine’s Hospice or a previous donation
  • Do not provide payment details, passwords or security codes in response to an unexpected request
  • Do not open unexpected attachments or click suspicious links
  • Verify requests using contact information published on Saint Catherine’s Hospice official website

Saint Catherine’s Hospice has not changed its banking details and will never ask you to provide a password or security code.

What is Saint Catherine’s Hospice doing?

We have reviewed the security of our systems, followed the security guidance provided by Beacon and assessed the information held within our account.

We have reported the incident to the Information Commissioner’s Office and the Charity Commission.

Beacon has told us that it has contained the incident and is continuing its investigation with external cyber-security specialists.

How can I ask a question?

Please email questions or concerns wherever possible to:


beaconincident@saintcatherines.org.uk

Using this dedicated address will help us record and answer enquiries consistently while allowing our other hospice services to continue operating as usual.

We will respond as soon as reasonably possible and appreciate your patience.