If your charity uses Beacon CRM, you’ve probably seen the recent notification about a cyber security incident. Beacon has advised charities to assume that information stored in their system may have been accessed by an unauthorised third party.
Before you panic, it’s important to know that there is currently no evidence that payment card details have been compromised.
What Does This Mean for Your Charity?
Even though the issue happened at Beacon, your charity still has responsibilities for the supporter, donor, volunteer and beneficiary data you hold.
That means you need to:
- Understand what information may have been affected
- Assess the potential risk to the people whose data you hold
- Decide whether you need to report the incident
- Consider whether supporters, beneficiaries or others need to be informed
First Steps to Take
Check What Data You Store
Take a look at the information held in Beacon. This could include:
- Names and contact details
- Donation history
- Gift Aid records
- Volunteer information
- Beneficiary records
- Notes or uploaded documents
The type and sensitivity of the information you hold will help determine how serious the potential risk may be.
Check Links to Cloud-Stored Files
If you have stored links in Beacon to files held elsewhere, such as documents in SharePoint, OneDrive or another cloud file-sharing platform, you should review how those links have been shared.
Important: check that any links stored in Beacon cannot be accessed by “Anyone with the link”. If an unauthorised person obtained one of these links through the incident, they may be able to access the linked file without needing to sign in. |
For SharePoint and OneDrive, links should ideally be configured so that only people within your organisation can access them and users are required to sign in with their organisational account.
If you identify any anonymously accessible links that were stored in Beacon, consider removing or replacing those links and reviewing what information could have been accessed through them.
Microsoft guidance: How shareable links work in OneDrive and SharePoint
Review Connected Apps and Integrations
Beacon has said the incident involved a compromised access key rather than a normal user login. As a precaution, it is worth reviewing any systems connected to Beacon and checking any API keys, tokens or integrations you have configured.
Consider what those connections allow Beacon to access and whether any credentials, keys or tokens should be revoked or replaced.
Review Your Policies
If you have a data breach, data protection or incident response policy, now is the time to dig it out and follow the process you have already put in place.
Make sure you document what you have checked, what you have found and any decisions you have made. This can be particularly important if you later need to demonstrate how your charity responded to the incident.
Do You Need to Report It?
Every charity will be different.
For some organisations, the data involved may be limited to names and email addresses. For others, it could include more sensitive information relating to supporters, volunteers or beneficiaries.
Under UK data protection law, certain personal data breaches need to be reported to the Information Commissioner’s Office (ICO). Where a breach meets the threshold for reporting, the ICO says it should be reported without undue delay and within 72 hours of becoming aware of it.
Use the ICO’s personal data breach self-assessment tool to help determine whether your organisation needs to report the incident.
ICO guidance: 72 hours – how to respond to a personal data breach
If you are unsure whether you need to report the incident, seek advice sooner rather than later.
Be Alert to Phishing Scams
For many charities, one of the biggest ongoing risks may be criminals using information obtained during the incident to make scam emails, phone calls or messages look more convincing.
Someone who knows the name of a supporter, which charity they support and other information about their relationship with the organisation may be able to create a much more convincing phishing message.
It is therefore a good time to remind staff, volunteers and, where appropriate, supporters to be cautious of:
- Unexpected emails, calls or messages
- Suspicious links or attachments
- Requests for passwords or personal information
- Unexpected requests to sign in to an account
- Urgent requests for money or donations
- Messages claiming to relate to the Beacon incident
NCSC guidance: How to spot and report phishing scams
What Can We Learn From This?
Incidents like this are a reminder that cyber security isn’t just about protecting your own systems. It is also about understanding the suppliers, platforms and integrations you rely on every day.
When things settle down, consider:
- Reviewing who has access to your systems
- Enabling multi-factor authentication wherever possible
- Keeping a record of suppliers that hold or process your data
- Reviewing third-party integrations and API access
- Checking how SharePoint, OneDrive and other cloud files are shared
- Removing anonymous or unnecessarily broad sharing links
- Reviewing your data breach and incident response plans
- Providing regular cyber security awareness training
For charities, it may also be worth considering whether the incident needs to be handled through your wider governance and serious incident reporting processes, depending on the circumstances and impact.
Need a Hand?
If your charity would like some independent advice on cyber security, data protection, reviewing cloud sharing permissions or understanding the potential impact of the Beacon incident, our team is happy to help.
Sometimes having a second pair of eyes can make all the difference.
This article is intended as general guidance and should not be considered legal advice. If you are unsure of your obligations, seek advice from the ICO or an appropriate data protection or legal professional.


