HomeBeacon CRM Security IncidentNewsBeacon CRM Security Incident

Beacon CRM Security Incident

There has been a security incident affecting Beacon CRM (customer relationship management), a system used by The Wye and Usk Foundation and hundreds of other charities to manage information about our donors, partners and contacts.

What happened?

On 3 August 2026, Beacon informed us that an unauthorised party had gained access to its systems using compromised credentials. Copies of Beacon’s database backups were made and Beacon believes they were likely downloaded, although its investigation is continuing.

Though encrypted, the information potentially accessed includes names, contact details, donation dates and amounts and some recent correspondence on personal records.

Donor banking details and payment card information are not stored within our Beacon CRM system and have not been compromised.

What are the possible risks?

There is currently no evidence that your information has been published or misused, and we are not aware of any fraud or harm resulting from this incident.

However, the information could potentially be used to make phishing emails, telephone calls or fraudulent requests appear more convincing.

We recommend that all our supporters remain vigilant for any unexpected phone calls, messages, and emails, consider using strong passwords and take extra care clicking links or opening attachments in any emails that are unusual. 

For additional security tips, please consult this information page from the National Cyber Security Centre:  https://www.ncsc.gov.uk/guidance/data-breaches

What action has been taken?

Beacon is continuing its investigation with external cyber-security specialists and has alerted the relevant authorities. The Wye and Usk Foundation has completed all the recommended security actions as advised by Beacon. The Foundation has also formally reported the incident to the Information Commissioner’s Office (ICO). They have confirmed that they do not plan to make any further contact with us.

Next steps

Beacon and The Wye and Usk Foundation are taking this incident extremely seriously. Beacon have implemented immediate security measures to block unauthorised access and are enhancing safeguards to ensure this does not happen again.

The Wye & Usk Foundation will continue to monitor Beacon’s investigation and implement any further recommendations that arise.

We understand that this news may be concerning and we apologise for any worry and stress this incident may cause. If you have any questions or wish to raise any concerns with us you can email us at dataprotection@wyeuskfoundation.org

Simon Evans,

CEO The Wye & Usk FoundationÂ