Beacon Data Breach

We understand that news of the recent cyber attack involving Beacon’s CRM database may be concerning.

To support you, we have put together answers to some of the questions you may have.

If you would like to get in touch with us directly, please submit your enquiry using the form below. We will keep this page updated as more information becomes available.


What is Beacon?

Beacon is a Customer Relationship Management (CRM) database used by over 1000 charities, including the Rowland Hill Fund. The Rowland Hill Fund uses Beacon to manage information about supporters, volunteers and beneficiaries

What happened?

Beacon recently experienced a cyber security incident involving unauthorised access to its systems. On 3rd August, Beacon advised its customers, including the Rowland Hill Fund, that copies of database backups may have been accessed and potentially downloaded by an unauthorised third party.

While data is stored on the site in an encrypted state, Beacon says its experts have advised that, based on the available evidence, it is possible that the unauthorised third party responsible for this incident “would have been able to decrypt it before copying it” from the systems.

What information may have been affected?

Our third-party CRM provider, Beacon, is used by the Rowland Hill Fund to manage information about our applicants, alongside our donors and fundraisers. This may include details such as your name, date of birth, email address, postal address, telephone number, a summary of your application for assistance - potentially including sensitive information - and communication preferences.

Beacon has confirmed that unauthorised access to the system occurred, but at this stage, we do not have evidence that any specific individual's record was accessed, viewed or downloaded. 

However, because of the nature of the incident, we cannot rule out the possibility that information stored within the system may have been exposed.

Does this include sensitive information provided as part of my application?

Potentially, yes. Depending on your circumstances and the support you applied for, the CRM may contain a summary of the information that you shared to help us assess your application, including information relating to your health, well-being, housing circumstances, caring responsibilities, or other personal matters. We do not store supporting documentation, attachments, or your full application on Beacon. It is used to summarise cases only.

We understand that this information is particularly sensitive and appreciate the trust applicants place in us. We are treating this incident with the utmost seriousness and are working to understand the potential impact on those affected.

Does this mean my bank details or payment information have been compromised?

For most of our beneficiaries, grant payments are made to a third-party supplier (e.g. a landlord or goods provider). If an applicant provided personal bank details, we are unable to rule out the possibility that this information has been exposed.

If you have supported the Fund by donating or fundraising, our CRM system does not hold or process payment card details, bank account information or other financial payment data. You can find specific information about how your data may have been effected here.

What should I do?

Whilst Beacon cannot confirm exactly what data has been breached, it may be used by malicious actors to send phishing emails or make scam phone calls.

While the investigation continues, we recommend remaining vigilant for unexpected emails, text messages or phone calls from anyone, even if they appear to come from reputable sources such as charities, financial organisations or government agencies.

Do not click on links or open attachments from unknown or suspicious senders.

Please be particularly cautious about:  

·       Requests for password or security information  

·       Requests to make payments  

·       Unsolicited emails containing links or attachments    

What is the Rowland Hill Fund doing in response?

The Rowland Hill Fund has reported the incident to the Information Commissioner's Office (ICO). We are working with Beacon to understand the full impact of the breach.

As a Charity, we would like to support our community during this time by offering a 12-month fraud monitoring service, free of charge. To register your interest, please submit your details here.

We recognise that many applicants share personal and sensitive information with us when seeking support. We sincerely regret the concern this incident will cause.


Submit further queries regarding the breach