
The company, whose clients include English National Ballet, Sheffield Hospitals Charity, Chiswick House and Gardens Trust, London-based homeless charity The Upper Room and Motiv8, this week reported a breach in which “compromised credentials” were used to make copies of its database backups containing customers’ information.
The breach has echoes of a similar incident in 2021, when US cloud computing and education software giant Blackbaud admitted it had paid a ransomware to hackers to delete a copy of sensitive data stolen during a cyber-attack.
More than 30 universities, including Manchester, South Wales, Glasgow, Oxford Brookes, Liverpool and Leeds which also have coronavirus cases, were among 125 charitable organisations that contacted the Information Commissioner’s Office in that summer to report they had been affected by the breach.
Charities including the National Trust, Sue Ryder, Young Minds and Crisis were also affected.
For its part, Beacon CRM has urged all its charity customers to consider reporting the incident to the Information Commissioner’s Office, posting a statement on its website which read: “A personal data breach should be reported to the ICO unless it is unlikely to result in a risk to the rights and freedoms of individuals. Whether there is a risk will depend on the nature of the data that was stored in Beacon, and so will vary from organisation to organisation.”
It also called on charities to consider contacting their supporters “if there is likely to be a high risk to their rights and freedoms” under data protection law.
Beacon CRM said it became aware of the incident on July 29 and subsequently sought help from cybersecurity experts, with charities told on Tuesday.
The firm said it is working with the police, regulators and cybersecurity experts to find out what happened.
English National Ballet told The Register: “As one of Beacon CRM’s customers, English National Ballet was informed on August 3 2026 that an unauthorised third party had gained access to their system.
“English National Ballet has not received confirmation that our data was directly affected, however as a precaution we have informed all contacts as soon as possible that their data could potentially have been accessed. ENB take data privacy extremely seriously. We are doing everything we can to reduce the risk of anything similar happening in the future.”
Related stories
National Trust among 125 hit by Blackbaud hack in UK
Crisis donors hit as fears grow over Blackbaud breach
Clients demand answers as cloud giant admits breach


Be the first to comment on "UK charities rocked in Beacon CRM mass data breach"