Update about Beacon CRM Cyber Attack
- Nick Bibby
- Aug 10
- 2 min read
On 3 August 2026 our provider Beacon, which provides CRM software for SIET and many other charities, informed us that it had experienced a cyber-security incident. Beacon has confirmed that an unauthorised third party gained access to its systems, copies of customer database backups were made, and the available evidence suggests that those copies were downloaded.
Beacon has advised its customers, including the Trust, to assume that information stored within their accounts, including attachments, may have been involved. There is currently no evidence that the information has been published or misused.
What information may have been involved?
The Trust holds records on past recipients of our grants and some recent applicants. The information held in these records varies. It may include:
names and contact details;
the amount and purpose of grants applied for or made
notes or attachments connected with grant applications
Other than grant amounts, we do not hold any financial information in affected records.
At present, neither Beacon nor the Trust can confirm exactly which individual records were downloaded or viewed, due to the type of cyber-attack experienced.
What are the possible risks?
The information could potentially be used to make phishing, impersonation or attempted fraud more convincing. The disclosure of personal information could also cause distress or a loss of privacy.
There is currently no evidence that this has happened, but we are informing you so that you can remain alert and take sensible precautions.
What have we done?
taken legal advice on the incident
reported the incident to the Information Commissioner’s Office;
reviewed the types of information held in our Beacon account and assessed the potential risks;
reviewed and secured integrations and access credentials connected with Beacon;
followed Beacon’s immediate security recommendations; and
continued to monitor its investigation.
Beacon has told us that it has contained the incident and is continuing its investigation with external cyber-security specialists.
What should you do?
You do not need to take any immediate action, but we recommend that you:
be cautious of unexpected emails, telephone calls, text messages or social media messages;
be particularly careful about messages claiming to be from the Trust or from Beacon CRM
do not provide passwords, payment information or other personal details in response to an unexpected message;
do not click links or open attachments unless you are confident that the message is genuine; and
contact us directly if you receive anything suspicious claiming to be from the Trust.
More information
Further information on this incident is available on Beacon's website at https://www.beaconcrm.org/incident-faqs and on here on the Trust's website.
We are very sorry that this has happened and for any concern it may cause. We know that Beacon is widely used by a large number of charities and organisations which have been affected by this cyber security incident. One of those is the British Deaf Association, whose update to its members has been the model for ours.
.png)




Comments