Data Incident Involving Beacon CRM



Mercy in Action UK has been informed about a data security incident affecting Beacon, the customer relationship management (CRM) software we use to manage records of website and other online donations and online Gift Aid.

What happened?

On 29 July 2026, Beacon CRM identified that it had experienced a cyber-security incident. Beacon has told its customers that unauthorised access was gained using compromised credentials, and that copies of database backups were made and should be treated as likely downloaded by the unauthorised third party. Beacon notified Mercy in Action UK of the incident on [date you were notified].

Beacon has engaged external cyber-security specialists, taken steps to secure its systems, and notified the relevant authorities, including the Information Commissioner's Office (ICO). At this stage, there is no evidence that any data has been published or misused, but we are treating this matter seriously and acting on the basis that data may have been accessed.

What information may have been affected?

Mercy in Action UK uses Beacon only to hold records relating to donations made through our website and associated Gift Aid declarations and volunteers records. We do not hold shop donor or shop customer records, or any Gift Aid information relating to shop transactions, on Beacon.

The information that may have been affected therefore includes, where provided by website donors:

- Name, postal address and email address
- Donation history (amounts and dates)
- Gift Aid declaration status
- Communication preferences

What was not affected?

- Payment card and bank details were not affected. Beacon does not store card data. Donations made through our website are processed securely by Stripe, our payment processor, which is entirely separate from Beacon and was not part of this incident.
- Shop donor and shop customer records, which are not held on Beacon.

What we are doing?

- We are working directly with Beacon as they investigate the scope of the breach.
- We have reported this incident to the Information Commissioner's Office (ICO) and the Charity Commissioner’s.
- We are reviewing our own records to identify who may be affected and contacting those individuals directly.
- We are reviewing our data protection practices and our relationship with Beacon in light of this incident.

What you can do?

- Be alert to unexpected emails, calls or letters referencing your donation history with us, particularly anything asking you to make a payment or share further personal or financial information. We will never ask you to send money or card details by email in response to this incident.
- If you notice anything suspicious referencing your details, please report it to us at dataprotection@mercyinaction.org.uk and to Action Fraud at https://www.actionfraud.police.uk

Questions

If you have any questions or concerns, please contact us at (dataprotection@mercyinaction.org.uk / Alec Cobb)

We are very sorry this has happened and for any worry it may cause. We will update this page as we learn more from Beacon's ongoing investigation.