Statement Regarding Beacon CRM Cyber Security Incident

5 August 2026
Beacon breach

Beacon is a customer relationship management (CRM) platform used by many charities and third sector organisations, including Cyrenians. On Monday 3rd August, Beacon informed us of a cyber security incident that affected the data held by all organisations that use Beacon as their CRM.

Beacon has confirmed that an unauthorised third party gained access to its systems last week and that database backups were likely downloaded during the incident. Based on the information provided by Beacon and its cyber security advisers, organisations using the platform are being advised to proceed on the assumption that data stored within Beacon has been accessed. It is highly unlikely that we will ever be able to know for sure whether Cyrenian's data was affected.

At this stage, Cyrenians has no evidence that any personal information relating to our clients, supporters, donors, volunteers or partners has been misused. However, given the information provided by Beacon, we are treating this incident with the utmost seriousness and are acting on the basis that data held within the platform may have been affected.

Protecting the privacy and security of personal information entrusted to us is a responsibility we take extremely seriously. Since being notified of the incident, we have been working to understand the potential impact on Cyrenians and the individuals whose information we hold.

As part of our response, we have:

  • Reviewed the information provided by Beacon and its cyber security investigators.
  • Assessed the categories of personal data that may have been impacted.
  • Initiated our internal data breach response procedures.
  • Sought specialist advice to ensure we meet all relevant legal and regulatory obligations.
  • Begun communicating directly with potentially affected individuals where appropriate.
  • Continued to monitor updates from Beacon and relevant authorities as the investigation develops.

Beacon has confirmed that it has reported the incident to the Information Commissioner's Office (ICO) and has implemented a number of containment and security measures to prevent further unauthorised access. Cyrenians has also reported the breach to the ICO and is undertaking its own assessment of additional reporting requirements and further actions required under UK data protection legislation.

We understand that news of a potential data breach may cause concern. While many questions remain unanswered and the full extent of the data involved may never be known with certainty, we believe it is important to be open about the situation and to communicate proactively with those who may be affected.

As a precaution, we encourage everyone to remain vigilant for unexpected emails, phone calls, text messages or other communications requesting personal, financial or security information. If you receive any communication claiming to be from Cyrenians which seems unusual or suspicious, please contact us directly before responding.

We will continue to monitor the situation closely and will provide further updates if additional information becomes available.

Anyone with questions or concerns can contact us at:

fundraising@cyrenians.scot

We sincerely apologise for any concern this situation may cause and thank our clients, supporters, volunteers and partners for their understanding while investigations continue.

For real time updates from Beacon you can visit their incident FAQs page here: https://www.beaconcrm.org/incident-faqs