Beacon CRM Data Incident August 2026

Statement and information for members, supporters, volunteers, service users and beneficiaries

Last updated 04/09/2026 at 12:00

On 3 August 2026, Behçet’s UK was notified of a cyber security incident involving Beacon CRM, the third-party database system we use to hold information about our current and former members, supporters, volunteers, service users and beneficiaries.  We shared information about the incident with those affected that week and reported it to the Information Commissioner’s Office (ICO) and the Charity Commission.

Beacon has now completed its investigation and provided its final findings. Here is the latest information, including what happened, what information may have been involved and what you should do.

What happened?

Beacon has confirmed that an unauthorised third party gained access to its systems on 27 July 2026. A copy of Beacon’s database, which contains information belonging to all of its customers, including Behçet’s UK, was made.

Beacon cannot confirm exactly what information was taken. However, the amount of data downloaded suggests that the unauthorised third party may have taken a copy of the entire database, including information belonging to Beacon’s customers. This means that information held by Behçet’s UK may have been included.

There is no evidence that this was a targeted attack on Beacon or any specific Beacon customer, including Behçet’s UK. There is also no evidence that payment details held by payment processors have been compromised.

There is currently no evidence that any of the information has been published or shared online. Beacon has checked online sources where stolen information can sometimes appear and has found no mention of the incident or related data.

The unauthorised third party contacted Beacon towards the end of its investigation and said that any information they had taken would be deleted and would not be kept, sold or shared. Beacon did not respond to this message because it came from a criminal source and cannot verify whether the claim is true. Beacon has confirmed that its work was not influenced by this message.

Is the problem now fixed?

Beacon has contained the incident and fixed the security weakness that allowed the unauthorised access to happen.

Two independent cyber-security organisations have reviewed Beacon’s work. They found no evidence of any further unauthorised access or suspicious activity since the original incident was contained.

Beacon is now operating normally and has introduced additional security measures to help prevent a similar incident from happening again.

Read the full information and FAQs

Our Frequently Asked Questions section below answers key questions about the incident and contains practical advice on staying vigilant against potential scams, along with guidance on safely checking your records.

Frequently Asked Questions

Are my financial details or passwords safe?

Beacon has confirmed that there is no evidence that payment details held by payment processors were compromised.

You do not need to change any passwords for Behçet’s UK, as you do not have a login account with us.

Does this mean all my NHS or healthcare information has been breached?

No. Behçet’s UK does not have access to your NHS medical records, so your NHS records are not held in our Beacon CRM database.

However, information you have provided directly to Behçet’s UK may have been held in Beacon CRM. Depending on how you have interacted with us, this may include information relating to your Behçet’s, your health, or your involvement with Behçet’s UK.

Has my child’s information been involved?

If your child is a current or former junior member of Behçet’s UK, or you previously registered them to participate in a project or attend a Behçet’s UK event, their information may have been held in Beacon CRM.

We contacted the parents and guardians of children and young people under 18 who we identified as potentially affected in August 2026.

If you have concerns about information relating to your child or a young person, please contact us at dpo@behcetsuk.org.

Why did I receive an email from Behçet’s UK?

You received the email because your email address is linked to one or more records held by Behçet’s UK in Beacon CRM.

Beacon is the system we use to manage information about members, supporters, service users, donors, event attendees and other contacts.

Why did I receive a letter from Behçet’s UK?

You received a letter because your postal address is linked to one or more records held by Behçet’s UK in Beacon CRM.

Beacon is the system we use to manage information about members, supporters, service users, donors, event attendees and other contacts.

Was Behçet’s UK specifically targeted?

No. Beacon has found no evidence that the incident was targeted at Beacon itself or at any particular Beacon customer, including Behçet’s UK.

Are Beacon’s systems secure now?

Beacon has confirmed that the security weakness that allowed the unauthorised access has been fixed.

All credentials that could have been compromised were reset. Beacon’s external cyber-security experts found no evidence of any further unauthorised access or suspicious activity after the incident was contained.

A second independent cyber-security organisation also reviewed Beacon’s response and found no evidence of unauthorised activity after 28 July 2026.

Beacon has also introduced additional security measures following the incident to help prevent a similar incident from happening again.

What information may have been involved?

The information varies depending on how you have interacted with Behçet’s UK.

Based on our records, information held in Beacon CRM may include some or all of the following:

  • Name
  • Address
  • Email address
  • Telephone number
  • Gender
  • Ethnic origin
  • Date of birth
  • Record of donations or payments made to Behçet’s UK, including Gift Aid records;
  • Information you have provided to us in connection with our services and activities which may relate to your medical condition or your involvement with Behçet’s UK.

Not all categories of information apply to every person.

Can you email me to confirm exactly what details you hold for me?

If you want to check what contact details we hold for you, please call our admin team on 0345 130 7328, Monday to Friday.

For your security, we cannot confirm or reveal any personal data over email; our team will verify your identity and confirm your details securely over the phone.

If we cannot answer your call immediately, please leave a message and we will return your call as soon as possible.

Has my information been published or misused?

There is currently no evidence that information from this incident has been published, shared or misused.

Beacon has checked online sources where stolen information can sometimes appear and has found no mention of the incident or related data.

Towards the end of its investigation, the unauthorised third party contacted Beacon and indicated that they would delete any information they had taken and that no copy would be retained, sold or shared. Beacon did not respond to this contact and cannot independently verify this claim.

The independent review carried out for Beacon also confirmed that the available system logs cannot establish whether the copies of data made by the unauthorised third party were ultimately taken away.

We therefore recommend that you continue to remain vigilant, even though there is currently no evidence of misuse.

What should I do?

Although there is currently no evidence that your information has been misused, we recommend that you remain vigilant. In particular:

  • Be cautious of any unexpected emails, telephone calls or text messages asking for personal or financial information. Do not click on any links unless you have independently verified the sender by contacting them through an official, trusted phone number.
  • Be wary of unexpected contact about your health. Ignore or hang up on unexpected calls, texts or emails referring to your medical condition unless you can independently verify that they are from your GP, hospital or another trusted healthcare provider.
  • Verify unexpected contact from Behçet’s UK. If you receive a message claiming to be from Behçet’s UK that seems unusual, do not reply. Instead, contact us using our official telephone number below to check that it is genuine. Suspicious messages claiming to be from Behçet’s UK can be sent to dpo@behcetsuk.org.
  • Ignore fake login or security requests. You do not have a password for our system, so completely disregard any message asking you to “log in” or “create a password” to secure your data; and
  • Monitor your credit profile. As a general precaution against identity fraud, you can check your credit files periodically using free, trusted agencies like Experian, Equifax, or TransUnion.

How can I spot a suspicious message?

A scam message may look convincing and could include information that is correct. Take extra care if you notice any of the following:

  • Unexpected contact: The message arrives unexpectedly and asks you to respond, make a payment, confirm an account or provide personal information.
  • Pressure or urgency: The sender tells you to act immediately, warns that something bad will happen or tries to stop you checking the message.
  • An unusual sender address: The display name may say “Behçet’s UK”, but the actual email address may be unfamiliar, misspelt or unrelated to Behçet’s UK.
  • Links and attachments: The message asks you to follow a link, download a file or open an attachment that you were not expecting.
  • Requests for sensitive information: The sender asks for a password, bank details, payment-card information, security code or other private information.
  • Information that sounds familiar: A scammer may mention a real event, donation, membership or organisation to make the message appear genuine. Correct details do not always mean the message is safe.

What should I do if I receive a suspicious message?

  1. Stop and check. Do not respond, click a link or open an attachment.
  2. Contact the organisation separately. Type its known website address into your browser or use contact details that you already know are genuine.
  3. Tell Behçet’s UK. Send suspicious messages claiming to be from us to dpo@behcetsuk.org.
  4. Report suspicious emails and texts. Forward suspicious emails to report@phishing.gov.uk and suspicious text messages to 7726.
  5. Act quickly if money is involved. If you have shared bank details or lost money, contact your bank immediately. In England, Wales and Northern Ireland, report fraud to Report Fraud. In Scotland, contact Police Scotland by calling 101.

Where can I find official UK government advice?

For independent, expert guidance on how to protect yourself and your family following a data security incident, please review the official resources provided by the UK’s National Cyber Security Centre (NCSC):

Information Commissioner’s Office: Advice for individuals affected by a personal data breach

How can I check my credit files or protect myself against identity fraud?

Although there is currently no evidence that your information has been misused, you may wish to monitor your credit score.

You can check your files completely free of charge under UK law using these regulated agencies:

Note: Checking your own credit file using these consumer tools will not lower your credit score or rating in any way. It shows as a private check that is completely invisible to lenders.

For an extra layer of active protection against identity fraud, you can register for Cifas Protective Registration online via their official website cifas.org.uk. For a small fee, This tells any organisation that uses Cifas data to pay special attention when your details are used to apply for their products or services. Knowing you’re at risk, they’ll carry out extra checks to make sure it’s really you applying, and not a fraudster using your details.

What are Behçet’s UK doing to address the incident?

Protecting your personal information is extremely important to us. We have taken the following steps in response to the incident:

  • reviewed the categories of personal information held in Beacon CRM and the potential risks to our members, supporters and beneficiaries;
  • reported the incident to the Information Commissioner’s Office and Charity Commission;
  • worked with Beacon throughout its investigation and reviewed its final report;
  • reviewed the advice we provide to people who may be affected; and
  • are reviewing our own data retention practices to consider how we can minimise the amount of historic information held on third-party systems in future.

Can I read Beacon’s final incident report?

Yes. You can download and read the complete public Beacon Final Incident Report.

Please note that the report, including its appendices, contains detailed technical information and corporate IT security frameworks. It was written primarily for Beacon’s business customers and may not be easy to understand for individual users.

Where do I find updates?

Beacon has now published its final report and considers its investigation complete.

Beacon’s final report states that it does not expect further investigation to establish additional technical details. However, if any new information emerges that materially changes our understanding of the incident or the risks to our members and supporters, we will update this webpage.

I have another question

If you have a question that is not answered here, or an urgent concern, you can call us on 0345 130 7328 or email dpo@behcetsuk.org. If we cannot answer immediately, please leave a message and we will return your call.