Members using Beacon CRM
Important notice for NODA members using Beacon CRM
NODA is alerting members to a significant cyber-security incident involving Beacon CRM, a customer relationship management system used by charities and other voluntary organisations.
On 12 August 2026, Beacon reported that an unauthorised third party had made a copy of the database containing its customers’ data, including attachment files. Beacon’s current assessment is that all data contained within the database may have been exported and was likely available to the attacker in a readable format.
Members that do not use Beacon CRM are not affected by this incident and do not need to take any action.
Action required by Beacon CRM users
Any NODA member or society using Beacon CRM should act promptly and should not wait for Beacon’s final investigation report before assessing the possible impact.
Affected organisations should:
- Identify the personal information and attachments held within their Beacon account.
- Assume, for risk-assessment purposes, that this information may have been accessed or downloaded.
- Pay particular attention to sensitive information, including safeguarding records, health information, membership details, volunteer records, donation histories, bank information and identity documents.
- Record the assessment undertaken, decisions reached and actions taken.
- Consider whether the incident must be reported to the Information Commissioner’s Office.
- Consider whether affected individuals must be informed.
- If the organisation is a registered charity, consider whether a serious incident report should be made to its charity regulator.
- Check whether its insurers, legal advisers or other relevant parties should be notified.
- Remain alert to phishing messages or other fraudulent communications that may use compromised personal information.
Beacon has reported the incident to the Information Commissioner’s Office. However, Beacon’s report does not remove the separate responsibilities of each organisation using the system. Beacon acts as a data processor for its customers, while individual societies and charities will normally remain responsible for deciding how the personal information they hold is used and protected.
Under UK data-protection law, an organisation must notify the ICO when a personal-data breach is likely to result in a risk to people’s rights and freedoms. Where the risk is considered high, affected individuals must also be informed without undue delay.
Registered charity trustees should additionally consider whether the incident has caused, or risks causing, significant harm, loss or damage to their charity, beneficiaries, assets, services or reputation. If so, it may need to be reported as a serious incident even where a separate report has already been made to the ICO.
Clear and timely communication with members, volunteers, donors and other affected people will be important in maintaining trust.
Further information is available from:
- Beacon CRM’s incident update
- Charity Commission guidance for charities affected by the incident
- ICO personal-data breach guidance
- Charity Commission serious-incident reporting guidance
This notice provides general information to assist NODA members. Each organisation must assess its own circumstances and should obtain appropriate professional advice where necessary.
News
Members using Beacon CRM