top of page
Search

Update about Beacon CRM Cyber Attack

  • Writer: Nick Bibby
    Nick Bibby
  • Aug 10
  • 2 min read

On 3 August 2026 our provider Beacon, which provides CRM software for SIET and many other charities, informed us that it had experienced a cyber-security incident. Beacon has confirmed that an unauthorised third party gained access to its systems, copies of customer database backups were made, and the available evidence suggests that those copies were downloaded.


Beacon has advised its customers, including the Trust, to assume that information stored within their accounts, including attachments, may have been involved. There is currently no evidence that the information has been published or misused.


What information may have been involved?

The Trust holds records on past recipients of our grants and some recent applicants. The information held in these records varies. It may include:


  • names and contact details;

  • the amount and purpose of grants applied for or made

  • notes or attachments connected with grant applications


Other than grant amounts, we do not hold any financial information in affected records.

At present, neither Beacon nor the Trust can confirm exactly which individual records were downloaded or viewed, due to the type of cyber-attack experienced.


What are the possible risks?

The information could potentially be used to make phishing, impersonation or attempted fraud more convincing. The disclosure of personal information could also cause distress or a loss of privacy.


There is currently no evidence that this has happened, but we are informing you so that you can remain alert and take sensible precautions.


What have we done?


  • taken legal advice on the incident

  • reported the incident to the Information Commissioner’s Office;

  • reviewed the types of information held in our Beacon account and assessed the potential risks;

  • reviewed and secured integrations and access credentials connected with Beacon;

  • followed Beacon’s immediate security recommendations; and

  • continued to monitor its investigation.


Beacon has told us that it has contained the incident and is continuing its investigation with external cyber-security specialists.


What should you do?

You do not need to take any immediate action, but we recommend that you:

  • be cautious of unexpected emails, telephone calls, text messages or social media messages;

  • be particularly careful about messages claiming to be from the Trust or from Beacon CRM

  • do not provide passwords, payment information or other personal details in response to an unexpected message;

  • do not click links or open attachments unless you are confident that the message is genuine; and

  • contact us directly if you receive anything suspicious claiming to be from the Trust.


More information

Further information on this incident is available on Beacon's website at https://www.beaconcrm.org/incident-faqs and on here on the Trust's website.


We are very sorry that this has happened and for any concern it may cause. We know that Beacon is widely used by a large number of charities and organisations which have been affected by this cyber security incident. One of those is the British Deaf Association, whose update to its members has been the model for ours.

 
 
 

Comments


Registration

SIET is a Registered Charity 

SIET is a  charity registered in Scotland: SC009207

Contact us

Address

Scottish International Education Trust
c/o Turcan Connell LLP, 

Princes Exchange,

1 Earl Grey St,

Edinburgh EH3 9EE

Policies

Website policies and statements

Our privacy and data policy is available here, this site's terms of use are available here, our cookie policy is here, and our accessibility statement is here

©2025 SIET.

bottom of page