Beacon CRM, a fundraising platform used by more than 1,500 charities, confirmed a cyberattack in which database backups were copied and likely downloaded. The company warned customers to assume everything stored on the platform, including attachment files, was taken, and that encrypted data may have been readable by the attackers.
Beacon said early evidence points to compromised credentials and that anyone with a paid account or free trial created before July 27 should treat all stored data as exposed. It reset every user’s password and imposed stronger replacement requirements. One affected charity said Beacon became aware of the attack on July 29; the Molly Rose Foundation was notified August 3.
Confirmed victims include the Molly Rose Foundation, English National Ballet, Chiswick House and Gardens Trust, UK-Med, Motiv8, and Macmillan Cancer Support Jersey. Affected data spans names, addresses, emails, phone numbers, genders, dates of birth, and donation records. The Scottish Council for Voluntary Organisations warned that many Scottish charities use the platform.
The incident compounds a grim month for the UK charity sector. CAF Bank, owned by the Charities Aid Foundation, kept online banking offline for more than ten days after detecting attempted fraudulent activity on July 21 and a second, related incident targeting user logins on July 25. The bank reopened the service August 4 but warned of further outages, waiving monthly account charges for August and September.
