Data Incident August 2026

Statement and information for members, supporters, volunteers, service users and beneficiaries

Last updated 03/09/2026 at 17:47

On Monday 3 August 2026, Behçet’s UK was informed about a cyber security incident affecting Beacon CRM, the third-party database system we use to hold information about our current and former members, supporters, volunteers, service users and beneficiaries.

Beacon CRM has now completed its investigation into the cyber security incident reported in August and has published its final report.

Beacon has confirmed that an unauthorised third party gained access to its systems on 27 July 2026 using a compromised AWS access key. Its investigation found evidence of substantial data downloads and, based on the volume of data transferred, Beacon’s assessment is that the entire database was exported. This database contained data relating to Behçet’s UK members, supporters, volunteers, service users and beneficiaries, as well as information belonging to other organisations using Beacon.

Beacon has confirmed that it cannot determine exactly which individual records were accessed or prove whether the downloaded data was ultimately taken away. However, it has taken the precautionary position that the data was exported and we are therefore continuing to treat the information we held on Beacon as potentially affected by this incident.

There is currently no evidence that information from the incident has been published or shared online. Beacon’s dark web monitoring has found no mention of the incident or related data. The person responsible also contacted Beacon and claimed that any data they had taken would be deleted and not retained, sold or shared. However, Beacon did not respond to this contact and cannot independently verify the claim.

Beacon has confirmed that the vulnerability which enabled the attack has been remediated. Its external cyber security experts found no evidence of ongoing unauthorised access following containment of the incident. An independent review by CYFOR Secure also found no sign of unauthorised activity after 28 July and confirmed that the access route had been closed and the relevant credentials replaced.

We know that many of our members, supporters and beneficiaries have entrusted us with highly personal information. We take that responsibility extremely seriously and are sincerely sorry for the concern and distress this situation may have caused.

Our Frequently Asked Questions section below answers key questions about the incident and contains practical advice on staying vigilant against potential scams, along with guidance on safely checking your records.

You can download and read the complete public Beacon Final Incident Report. Please note that the report, including the appendices, which contain complex corporate IT security frameworks, is meant for business clients rather than individual users.

If you are concerned or have any questions, please get in touch with us by email at: dpo@behcetsuk.org or by phone on 0345 130 7328

Frequently Asked Questions

Are my financial details or passwords safe?

Behçet’s UK does not store debit or credit card details or bank account details in Beacon CRM.

Beacon has confirmed that there is no evidence that payment details held by payment processors were compromised.

You do not need to change any passwords for Behçet’s UK, as you do not have a login account with us.

Does this mean all my healthcare information has been breached?

No. Behçet’s UK does not have access to your NHS medical records, so your NHS records are not held in our Beacon CRM database.

However, information you have provided directly to Behçet’s UK may have been held in Beacon CRM. Depending on how you have interacted with us, this may include information relating to your Behçet’s, your health, or your involvement with Behçet’s UK.

Beacon’s final assessment is that the entire database was exported, so we are treating information we held in Beacon as potentially affected by this incident.

Has my child’s information been involved?

If your child was a junior member of Behçet’s UK, or you previously registered them to participate in a project or attend a Behçet’s UK event, their information may have been held in Beacon CRM.

Beacon’s final assessment is that almost all accounts in its database were affected, apart from accounts that had been deleted more than 30 days before 27 July 2026.

We contacted the parents and guardians of children and young people under 18 who we identified as potentially affected in August.

If you have concerns about information relating to your child or a young person, please contact us at dpo@behcetsuk.org.

Why did I receive an email from Behçet’s UK?

You received the email because your email address is linked to one or more records held by Behçet’s UK in Beacon CRM.

Beacon is the system we use to manage information about members, supporters, service users, donors, event attendees and other contacts.

Why did I receive a letter from Behçet’s UK?

You received a letter because your postal address is linked to one or more records held by Behçet’s UK in Beacon CRM.

Beacon is the system we use to manage information about members, supporters, service users, donors, event attendees and other contacts.

What happened?

On 27 July 2026, an unauthorised third party gained access to Beacon’s systems using a compromised Amazon Web Services (AWS) access key.

Beacon’s investigation found evidence of a significant increase in data transfer from its systems on 27 and 28 July, indicating that substantial downloads occurred.

Based on the volume of data transferred, Beacon’s assessment is that the unauthorised third party exported the entire Beacon database, which contained data and attachment files relating to its customers, including Behçet’s UK.

Beacon cannot determine exactly which individual records or files were accessed, or prove whether the downloaded data was ultimately taken away. However, it has taken the precautionary position that the data was exported.

Was Behçet’s UK targeted directly by hackers?

No.

Beacon has found no evidence that the attack was targeted at Beacon itself or at any particular Beacon customer. The incident affected Beacon’s wider database environment.

Are Beacon’s systems secure now?

Beacon has confirmed that the vulnerability that enabled the unauthorised access has been remediated.

All credentials that could have been compromised were reset. Beacon’s external cyber security experts found no evidence of ongoing unauthorised access following containment of the incident.

An independent cyber security organisation, CYFOR Secure, also reviewed Beacon’s response. It found no sign of unauthorised activity after 28 July 2026 and confirmed that the access route had been closed, the relevant credentials replaced and no mechanisms had been left behind that would allow the attacker to regain access.

Beacon has also introduced additional security measures following the incident, including more frequent penetration testing, automated scanning for exposed keys and additional independent security assessments.

What information may be involved?

The information varies depending on how you have interacted with Behçet’s UK.

Based on our records, information held in Beacon CRM may include some or all of the following:

  • Name
  • Address
  • Email address
  • Telephone number
  • Gender
  • Ethnic origin
  • Date of birth
  • Record of donations or payments made to Behçet’s UK including Gift Aid records;
  • Information you have provided to us in connection with our services and activities which may relate to your medical condition or your involvement with Behçet’s UK.

Not all categories of information apply to every person.

Can you email me to confirm exactly what details you hold for me?

If you want to check what contact details we hold for you, please call our admin team on 0345 130 7328, Monday to Friday.

For your security, we cannot confirm or reveal any personal data over email; our team will verify your identity and confirm your details securely over the phone.

Please note that as a small charity with only two part-time staff, we may need to return your call. Please leave a message and we will get back to you as soon as possible.

Has my information been published or misused?

There is currently no evidence that information from this incident has been published or shared online.

Beacon’s dark web monitoring has found no mention of the incident or related data online.

Towards the end of its investigation, the person responsible contacted Beacon and indicated that they would delete any data they had exfiltrated and that no copy would be retained, sold or shared. Beacon did not respond to this contact and cannot independently verify this claim.

The independent review carried out for Beacon also confirmed that the available system logs cannot establish whether the copies of data made by the attacker were ultimately taken away.

We therefore recommend that you continue to remain vigilant, even though there is currently no evidence of misuse.

What should I do?

Although there is currently no evidence that your information has been misused, we recommend that you remain vigilant. In particular:

  • Be cautious of any unexpected emails, telephone calls or text messages asking for personal or financial information. Do not click on any links unless you have independently verified the sender by contacting them through an official, trusted phone number.
  • Be wary of unexpected contact about your health. Ignore or hang up on unexpected calls, texts or emails referring to your medical condition unless you can independently verify that they are from your GP, hospital or another trusted healthcare provider.
  • Verify unexpected contact from Behçet’s UK. If you receive a message claiming to be from Behçet’s UK that seems unusual, do not reply. Instead, contact us using our official telephone number below to check that it is genuine. Suspicious messages claiming to be from Behçet’s UK can be sent to dpo@behcetsuk.org.
  • Ignore fake login or security requests, as you do not have a password for our system; completely disregard any message asking you to “log in” or “create a password” to secure your data; and
  • Monitor your credit profile. As a general precaution against identity fraud, you can check your credit files periodically using free, trusted agencies like Experian, Equifax, or TransUnion.

How can I spot a suspicious message?

A scam message may look convincing and could include information that is correct. Take extra care if you notice any of the following:

  • Unexpected contact: The message arrives unexpectedly and asks you to respond, make a payment, confirm an account or provide personal information.
  • Pressure or urgency: The sender tells you to act immediately, warns that something bad will happen or tries to stop you checking the message.
  • An unusual sender address: The display name may say “Behçet’s UK”, but the actual email address may be unfamiliar, misspelt or unrelated to Behçet’s UK.
  • Links and attachments: The message asks you to follow a link, download a file or open an attachment that you were not expecting.
  • Requests for sensitive information: The sender asks for a password, bank details, payment-card information, security code or other private information.
  • Information that sounds familiar: A scammer may mention a real event, donation, membership or organisation to make the message appear genuine. Correct details do not always mean the message is safe.

What should I do if I receive a suspicious message?

  1. Stop and check. Do not respond, click a link or open an attachment.
  2. Contact the organisation separately. Type its known website address into your browser or use contact details that you already know are genuine.
  3. Tell Behçet’s UK. Send suspicious messages claiming to be from us to dpo@behcetsuk.org.
  4. Report suspicious emails and texts. Forward suspicious emails to report@phishing.gov.uk and suspicious text messages to 7726.
  5. Act quickly if money is involved. If you have shared bank details or lost money, contact your bank immediately. In England, Wales and Northern Ireland, report fraud to Report Fraud. In Scotland, contact Police Scotland by calling 101.

Where can I find official UK government advice?

For independent, expert guidance on how to protect yourself and your family following a data security incident, please review the official resources provided by the UK’s National Cyber Security Centre (NCSC):

Information Commissioner’s Office: Advice for individuals affected by a personal data breach

How can I check my credit files or protect myself against identity fraud?

Although there is currently no evidence that your information has been misused, you may wish to monitor your credit score.

You can check your files completely free of charge under UK law using these regulated agencies:
Experian: Access your files directly via the official Experian app or website.

Equifax: Check your report for free via ClearScore.

TransUnion: Check your report for free via Credit Karma or the MoneySavingExpert Credit Club.

Note: Checking your own credit file using these consumer tools will not lower your credit score or rating in any way. It shows as a private check that is completely invisible to lenders.

For an extra layer of active protection against identity fraud, you can register for CIFAS Protective Registration online via their official website cifas.org.uk. For a small fee, this places a secure flag on your credit file for two years. This legally obligates UK lenders and banks to run strict, manual verification checks to confirm your identity before approving any new loans, credit cards, or accounts in your name.

What are Behçet’s UK doing to address the incident?

Protecting your personal information is extremely important to us. Following the conclusion of Beacon’s primary investigation, we have taken the following definitive steps:

  • reviewed the categories of personal information held in Beacon CRM and the potential risks to our members, supporters and beneficiaries;
  • reported the incident to the Information Commissioner’s Office and Charity Commision;
  • worked with Beacon throughout its investigation and reviewed its final report;
  • reviewed the advice we provide to people who may be affected; and
  • begun reviewing our own data retention practices to consider how we can minimise the amount of historic information held on third-party systems in future.

Where do I find updates and what happens next?

Beacon has now published its final report and considers its investigation complete.

Beacon’s final report states that it does not expect further investigation to establish additional technical details. However, if any new information emerges that materially changes our understanding of the incident or affects you directly, we will update this webpage.

If you have any urgent concerns, you can call us on 0345 130 7328 or email dpo@behcetsuk.org. As we are a small charity with only two part-time staff, please leave a message if we cannot answer immediately, and we will return your call.