Beacon Data Breach

We sincerely regret the concern this incident will cause and are committed to providing clear updates and appropriate support while the investigation continues. To support you, we have put together answers to some of the questions you may have. If you would like to get in touch with us directly, please submit your enquiry using the form below. We will keep this page updated as more information becomes available.

What is Beacon?

Beacon is a Customer Relationship Management (CRM) database used by over 1000 charities, including Rowland Hill Fund. The Rowland Hill Fund uses Beacon to manage information about supporters, volunteers and beneficiaries

What happened?

Beacon recently experienced a cyber security incident involving unauthorised access to its systems. Beacon has advised its customers, including the Rowland Hill Fund, that copies of database backups may have been accessed and potentially downloaded by an unauthorised third party.

What information about me may have been affected?
Our third-party CRM provider, Beacon, is used by the Rowland Hill Fund to manage information about our applicants, donors, supporters and event attendees. This may include details such as your name, email address, postal address, telephone number, application summary, and communication preferences.  

Beacon has confirmed that unauthorised access to the system occurred, but at this stage, we do not have evidence that any specific individual's record was accessed, viewed or downloaded.   

However, because of the nature of the incident, we cannot rule out the possibility that information stored within the system may have been exposed.  

Does this mean my bank account or payment card information affected?
No. The CRM system does not hold or process payment card details, bank account information or other financial payment data.

Should I cancel my donation?

All donations to the charity are handled outside of Beacon and therefore no card details are stored on there. However, we understand if you do not feel comfortable donating at this moment in time. Please clarify what method(s) you use to donate, and we can action this.

What should I do to protect myself?
We recommend remaining vigilant for any unexpected emails, telephone calls, text messages, or letters requesting personal information. Be particularly cautious if someone contacts you claiming to know details about your application or circumstances and asks for further information.  

We will never ask you to provide passwords, payment card details, or sensitive personal information through unsolicited communications. If you are unsure whether a communication is genuine, please contact us directly using our official contact details.  

What is the charity doing to support applicants and protect their information?

 Protecting the privacy and dignity of our applicants is a priority. Since becoming aware of the incident, we have been working closely with Beacon to investigate what happened, assess the risks to individuals, and ensure appropriate security measures are in place.  

We are also meeting our legal and regulatory obligations and will continue to provide updates as more information becomes available. If we become aware of any specific risks to applicants, we will communicate these promptly along with guidance on any steps that may need to be taken.  

How will I be notified if my data was accessed?
At present, neither we nor the Rowland Hill Fund or Beacon can determine whether any specific individual's record was accessed, viewed, or downloaded because of this incident. For that reason, we are unable to identify and notify affected individuals on a record-by-record basis.  

We are informing all supporters whose information may have been held within the affected system so that everyone is aware of the potential risk and can take appropriate precautions. If new information becomes available during the investigation that indicates your information was specifically affected, we will contact you directly using the contact details we hold for you.  

We are committed to providing updates as our understanding of the incident develops and will communicate any significant findings as soon as possible.  

Please note: Because it is not possible to determine which records, if any, were accessed, we are notifying all potentially affected individuals.