Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Healthcare and Victim Support Charities Affected by Beacon Cyber Incid

August 7, 2026

Where AI Platforms like Claude Actually Fit

August 7, 2026

Google Links Redact Extortion Group to BlackFile Rebrand

August 7, 2026
Facebook X (Twitter) Instagram
Friday, August 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Healthcare and Victim Support Charities Affected by Beacon Cyber Incid
News

Healthcare and Victim Support Charities Affected by Beacon Cyber Incid

Team-CWDBy Team-CWDAugust 7, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Around 1500 UK charities have potentially suffered data breaches following a cyber incident impacting third-party CRM provider Beacon.

Personal details held by these charities, including those operating in sensitive areas such as healthcare and victim support, are believed to have been accessed, copied and likely exfiltrated by an unauthorized actor.

Beacon offers a specialized CRM platform to charities and holds data for around 1500 voluntary sector organizations.

In a statement sent to Infosecurity on August 6, a Beacon spokesperson revealed that the software provider has notified “all” its customers of the incident.

“Our focus is now on supporting them as much as possible in any onward communication of their own regarding potential data impact,” the spokesperson continued.

Since the incident was first publicly disclosed by Beacon on August 4, 2026, numerous UK-based charities have revealed that their databases were among those accessed, potentially impacting supporters.

These include Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity and Rowcroft Hospice in the healthcare sector, homelessness charity the Clock Tower Sanctuary and Victim Support.

The type of data thought to have been affected includes names, email addresses, telephone numbers and donation records. Beacon said that its customers should assume all data they store in its platform, including attachments, has been downloaded.

The company said it observed a “spike in activity” during the incident timeline that is symptomatic of data leaving its systems.

“If you were storing data about people in your Beacon account, it is likely to have been downloaded and as such you need to evaluate whether you must in turn notify the people you store in Beacon,” Beacon wrote in its incident update from August 4.

While the stored data was in an encrypted state, Beacon said it is possible that the unauthorised actor has been able to decrypt it.

The compromised CRM system does not hold sensitive patient information, payment card details or bank account information.

Beacon has informed customers that they can safely continue to collect payments via Beacon forms, but they must follow the steps in the Security Incident Response Guide in order to update their payment providers and apps.

Impacted charities have also been told to report the breach to the UK’s Information Commissioner’s Office (ICO).

Compromised Credentials Led to Data Breach

Beacon revealed in its public statement that a compromised access key was used to gain access to its systems. No details have been provided as to how this key was obtained.

“This was more sophisticated than a simple compromised username and password,” the CRM provider noted.

In its statement to Infosecurity, Beacon said the incident has now been contained with the assistance of external cybersecurity experts, who have launched an investigation into the full circumstances of the incident.

“Since containing the initial incident, we have not identified or observed any ongoing unauthorised access to Beacon’s systems. Our customers continue to access our platform and services as normal,” the spokesperson confirmed.

What the Incident Could Mean for Charity Victims

The cyber-attack has not yet been attributed to a specific threat actor, and it remains unclear what their objectives were or how they intend to use any compromised data.

No data linked to the incident has appeared on the dark web to date.

In other incidents involving the compromise of data held by third-party services, attackers have extorted victim organizations, threatening to make the stolen information public unless a payment is made. This occurred in the campaign that impacted Snowflake customer instances in 2024.

Commenting on the incident, Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said that the charitable sector is a “persistently underappreciated target” when it comes to cyber-attacks.

“Donor databases hold exactly the kind of personally identifiable information – names, addresses, giving history, Gift Aid declarations linking financial behavior to identity that enables targeted fraud and social engineering,” he said.

“The assumption that charities are too small or too mission-driven to be worth targeting is precisely what makes them attractive. Security investment in the sector is typically minimal, third-party platform dependency is high, and the reputational stakes of a breach are significant for organizations whose entire model depends on donor trust,” Patel explained.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWhere AI Platforms like Claude Actually Fit
Team-CWD
  • Website

Related Posts

News

Where AI Platforms like Claude Actually Fit

August 7, 2026
News

Google Links Redact Extortion Group to BlackFile Rebrand

August 7, 2026
News

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

August 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A phishing attack that doesn’t steal your password

June 15, 2026

Chronology of a Skype attack

February 5, 2026

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.