Data Incident August 2026

Statement and information for members, supporters, volunteers, service users and beneficiaries

Last updated 14/08/2026 at 11:00

On Monday 3 August 2026, Behçet’s UK was informed about a cyber security incident affecting Beacon CRM, the third-party database system we use to hold information about our current and former members, supporters, volunteers, service users, and beneficiaries.

An update on the incident (14/08/26)
Beacon has now confirmed that an unauthorised third party bypassed their security systems and exported a copy of their central database backups. This was part of a broad attack affecting over 1,000 UK charities and organisations that use Beacon’s platform. Unfortunately, our assessment is that the data relating to Behçet’s UK was included in this export.

The most important reassurance we can give you is that there is absolutely no evidence that any data has been published, shared, or misused online. Furthermore, Beacon has permanently closed the security flaw and put advanced, 24/7 monitoring systems in place to secure their environment moving forward.

We know that many of our members, supporters, and beneficiaries have entrusted us with highly personal information. We take that responsibility extremely seriously and are sincerely sorry for any concern and distress this situation may cause.

Our detailed Frequently Asked Questions section below answers key questions about the incident and contains practical advice on staying vigilant against potential scams, along with guidance on safely checking your records.

In the meantime, if you are concerned or have any questions, please get in touch with us by email at: dpo@behcetsuk.org or by phone on 0345 130 7328

Frequently Asked Questions

Are my financial details or passwords safe?

Beacon has said there is no evidence that bank account details or debit/credit card information are compromised, as these are not stored in the system.

You do not need to change any passwords for Behçet’s UK, as you do not have a login account with us.

Does this mean all my healthcare information has been breached?

No. Please be reassured that we do not have access to your NHS medical records, so your full healthcare and medical history is entirely safe.

The information involved is strictly limited to what you have shared with Behçet’s UK directly. In terms of health context, for most this people is usually just a brief outline, such as your membership category (e.g., whether you registered as a patient, carer, family member, or supporter) or any notes from past email correspondence with us.

Has my child’s information been involved?

If your child is a junior member of Behçet’s UK, or if you have previously registered them to participate in a project or attend our Friends and Family Day, their information may be involved.

To ensure parents and guardians are informed, we sent a specific email on Tuesday 4 August 2026 to the parents and guardians of all children and young people under the age of 18 who may be affected. If you did not receive that email, your child’s data is highly unlikely to be part of this incident. If you remain concerned, please contact us securely at dpo@behcetsuk.org.

Why did I receive an email from Behçet’s UK?

You received the email because your email address is linked to one or more records held by Behçet’s UK in Beacon CRM.

Beacon is the system we use to manage information about members, supporters, service users, donors, event attendees and other contacts.

Why did I receive a letter from Behçet’s UK?

You received a letter because your postal address is linked to one or more records held by Behçet’s UK in Beacon CRM.

Beacon is the system we use to manage information about members, supporters, service users, donors, event attendees and other contacts.

What happened?

On Monday 3 August 2026, Behçet’s UK was informed about a cyber security incident involving Beacon CRM, the third-party database system we use to hold information about our current and former members, supporters, volunteers, service users, and beneficiaries.

According to Beacon’s finalized investigation, an unauthorised third party gained access to their systems using a compromised AWS (Amazon Web Services) access key on 27–28 July 2026. The hacker used this access to export and download a copy of the central database backups containing information from multiple client organisations, including Behçet’s UK.

While the data was copied, there is still no evidence from ongoing dark web and online monitoring that any of this information has been published, shared, or used for fraudulent purposes.

Was Behçet’s UK targeted directly by hackers?

No. Behçet’s UK was not specifically targeted.

The cyber security incident occurred at Beacon CRM, which is a widely used, secure database platform. Beacon supports over 1,000 charities and organisations across the UK, all of which have potentially been affected by this breach.

Are Beacon’s systems secure now?

Yes. Beacon remains fully operational and has completely closed the security flaw. They have successfully remediated the specific vulnerability, reset all access credentials integrated with Amazon Web Services (AWS), and deployed advanced SentinelOne Endpoint Detection and Response (EDR) software.

This security software continuously scans their environment 24/7 for suspicious activity. External cyber security experts have confirmed that there has been no further unauthorised access since the initial incident was contained.

What information may be involved?

We want to reassure you that Behçet’s UK does not hold passwords, nor do we store any debit/credit card or bank account details on this system. Therefore, no financial information or login credentials have been compromised.

The information varies depending on how you have interacted with Behçet’s UK. Based on our records, the information that may have been affected includes some or all of the following:

  • Name
  • Address
  • Email address
  • Telephone number
  • Gender
  • Ethnic origin
  • Date of birth
  • Record of donations or payments made to Behçet’s UK including Gift Aid records;
  • Information you have provided to us in connection with our services and activities which may relate to your medical condition or your involvement with Behçet’s UK.

Not all categories apply to every person.

Can you email me to confirm exactly what details you hold for me?

If you want to check what contact details we hold for you, please call our admin team on 0345 130 7328 between Monday and Friday.

For your security, we cannot confirm or reveal any personal data over email; our team will verify your identity and confirm your details securely over the phone.

Please note that as a small charity with only two part-time staff, we may need to return your call, so please leave a message and we will get back to you as soon as possible.

What should I do?

Although there is currently no evidence that your information has been misused, we recommend that you remain vigilant. In particular:

  • Be cautious of any unexpected emails, telephone calls or text messages asking for personal or financial information. Do not click on any links unless you have independently verified the sender by contacting them through an official, trusted phone number.
  • Be wary of unexpected contact about your health. Ignore or hang up on unexpected calls, texts or emails referring to your medical condition unless you can independently verify that they are from your GP, hospital or another trusted healthcare provider.
  • Verify unexpected contact from Behçet’s UK. If you receive a message claiming to be from Behçet’s UK that seems unusual, do not reply. Instead, contact us using our official telephone number below to check that it is genuine. Suspicious messages claiming to be from Behçet’s UK can be sent to dpo@behcetsuk.org.
  • Ignore fake login or security requests, as you do not have a password for our system; completely disregard any message asking you to “log in” or “create a password” to secure your data; and
  • Monitor your credit profile. As a general precaution against identity fraud, you can check your credit files periodically using free, trusted agencies like Experian, Equifax, or TransUnion.

How can I spot a suspicious message?

A scam message may look convincing and could include information that is correct. Take extra care if you notice any of the following:

  • Unexpected contact: The message arrives unexpectedly and asks you to respond, make a payment, confirm an account or provide personal information.
  • Pressure or urgency: The sender tells you to act immediately, warns that something bad will happen or tries to stop you checking the message.
  • An unusual sender address: The display name may say “Behçet’s UK”, but the actual email address may be unfamiliar, misspelt or unrelated to Behçet’s UK.
  • Links and attachments: The message asks you to follow a link, download a file or open an attachment that you were not expecting.
  • Requests for sensitive information: The sender asks for a password, bank details, payment-card information, security code or other private information.
  • Information that sounds familiar: A scammer may mention a real event, donation, membership or organisation to make the message appear genuine. Correct details do not always mean the message is safe.

What to do

  1. Stop and check. Do not respond, click a link or open an attachment.
  2. Contact the organisation separately. Type its known website address into your browser or use contact details that you already know are genuine.
  3. Tell Behçet’s UK. Send suspicious messages claiming to be from us to dpo@behcetsuk.org.
  4. Report suspicious emails and texts. Forward suspicious emails to report@phishing.gov.uk and suspicious text messages to 7726.
  5. Act quickly if money is involved. If you have shared bank details or lost money, contact your bank immediately. In England, Wales and Northern Ireland, report fraud to Report Fraud. In Scotland, contact Police Scotland by calling 101.

Where can I find official UK government advice?

For independent, expert guidance on how to protect yourself and your family following a data security incident, please review the official resources provided by the UK’s National Cyber Security Centre (NCSC):

Information Commissioner’s Office: Advice for individuals affected by a personal data breach

How can I check my credit files or protect myself against identity fraud?

Although there is currently no evidence that your information has been misused, you may wish to monitor your credit score.

You can check your files completely free of charge under UK law using these regulated agencies:
Experian: Access your files directly via the official Experian app or website.

Equifax: Check your report for free via ClearScore.

TransUnion: Check your report for free via Credit Karma or the MoneySavingExpert Credit Club.

Note: Checking your own credit file using these consumer tools will not lower your credit score or rating in any way. It shows as a private check that is completely invisible to lenders.

For an extra layer of active protection against identity fraud, you can register for CIFAS Protective Registration online via their official website cifas.org.uk. For a small fee, this places a secure flag on your credit file for two years. This legally obligates UK lenders and banks to run strict, manual verification checks to confirm your identity before approving any new loans, credit cards, or accounts in your name.

What are Behçet’s UK doing to address the breach?

Protecting your personal information is extremely important to us. Following the conclusion of Beacon’s primary investigation, we have taken the following definitive steps:

  • Reviewed all categories of data held on our platform to ensure our members receive accurate, specific risk advice.
  • Formally reported the incident to the Information Commissioner’s Office (ICO).
  • Confirmed that Beacon successfully patched the vulnerability and deployed live 24/7 endpoint monitoring software.
  • Committed to reviewing our own data retention policies to minimize the amount of historic information held on third-party systems moving forward.

Where do I find updates and what happens next?

We are committed to complete transparency. Beacon has advised that this represents their final position and they do not expect further investigation to uncover more technical details. However, if any new information emerges that materially changes our understanding or impacts you directly, we will post it to this webpage immediately.

If you have any urgent concerns, you can call us on 0345 130 7328 or email dpo@behcetsuk.org. As we are a small charity with only two part-time staff, please leave a message if we cannot answer immediately, and we will return your call.