"Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorized third-party," Beacon CRM said on Tuesday.
Beacon CRM: confirmation, scope and immediate guidance
Beacon CRM, a supplier of fundraising and constituent-management software with more than 1,500 customers, has acknowledged a cyberattack that appears to have resulted in large-scale copying of customer databases. The company said its investigation is ongoing, but warned users to "assume that all data that you store in Beacon, including attachment files, has been downloaded." Beacon added that although customer data is encrypted, "it is possible that the unauthorized third party responsible for this incident was able to decrypt it," and therefore customers should assume copied information was readable.
Timeline and account rules: July 27–August 3
Beacon told customers that anyone with a paid account or a free trial created before July 27 should assume their stored data was downloaded. One affected charity said Beacon became aware of the incident on July 29. The Molly Rose Foundation said Beacon informed it of the situation on August 3—five days after Beacon became aware, according to the foundation. As an immediate mitigation step, Beacon reset every user's password and imposed stronger requirements on the replacement passwords, and it urged customers to investigate how badly they were affected.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security lead →Named charities and the types of data exposed
Because Beacon CRM focuses on the charity sector, most of the customers confirmed as affected are UK charities. Among those named as affected are the Molly Rose Foundation, the Scottish Council for Voluntary Organisations (SCVO), London-based The Upper Room, Chiswick House and Gardens Trust, Macmillan Cancer Support Jersey (reported by the Bailiwick Express), Motiv8 (reported by Portsmouth News), UK-Med, English National Ballet, and PANS PANDAS UK. Victim Support was listed among affected customers but said no victim data was affected. PANS PANDAS UK said it was unsure whether its data had been affected, having abandoned Beacon earlier in the year.
The Molly Rose Foundation confirmed the breach affected personal data belonging to supporters, donors and service users, including names, addresses, email addresses, phone numbers, genders, dates of birth, records of donations or payments made to the foundation, and "other information supplied in connection with its services and activities."
Evidence of credential compromise and data exfiltration
Beacon's information page, cited by the reporting, indicated that early evidence points to compromised credentials being used to access its systems. The company said investigators have "evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems." Beacon explicitly stated that copies of database backups were made and likely downloaded by an unauthorized third party, while declining to comment to The Register on whether extortion demands were made or on specific details of how or when the attackers gained access.
What this means for technologists, charity leaders, and donors
- Technologists and security teams: will need to prioritise forensic review of account activity for sign-in anomalies and confirm whether local or offsite backups were involved; Beacon's reset of all passwords and stronger replacement rules are steps to contain credential misuse but teams must verify the integrity of exported data.
- Charity leaders and procurement leads: must assess the scope of exposure for their organisations—Beacon has urged customers to investigate how badly they were affected—and review the creation date of accounts (customers with accounts or trials created before July 27 were told to assume data was downloaded).
- Donors, supporters and service users: where charities report similar data types to those named by the Molly Rose Foundation, individuals should assume personal information such as names, contact details, dates of birth and donation records may have been copied and readable.
Conclusion: ongoing investigation, unanswered questions
Beacon's public confirmation describes a clear pattern—database backups copied and likely downloaded, a spike in activity consistent with exfiltration, and early indicators of credential compromise—but several practical questions remain unanswered in the statements Beacon provided and in responses to The Register. The company has taken immediate containment steps, notifying customers, forcing password resets and tightening password rules, and it has instructed customers to probe their own exposures. For the many UK charities that relied on Beacon, the practical effect is immediate: treat historical account data created before July 27 as compromised and proceed on the assumption that downloaded data may be readable until investigations prove otherwise.



