Skip to main content

Beacon IT security incident

10 August 2026

Ideally, when we update the Foothold community it is to talk about the support we provide, the generosity our community shows, and our impact and stories.

However, on this occasion, the reason for the update is something that is unfortunately becoming increasingly more frequent and affects many organisations at some point in time.

A week ago, we were informed by our CRM provider, Beacon, that it has experienced an IT security incident and that data belonging to the Foothold community may have been impacted. This is not unique to Foothold – we understand that every organisation that was using Beacon CRM at the time of the incident is unfortunately in the same position.

Beacon has been providing updates about the incident via its website, including an incident statement, incident guide and FAQs. We would encourage you to read these to better understand the nature and extent of what has happened. This information can be accessed here(opens in new tab).

In summary, we understand that an unauthorised third party used compromised credentials to access Beacon’s systems and then downloaded and took a copy of its database. We have been told by Beacon to work on the assumption that this includes data belonging to the Foothold community, though this has not been confirmed.

Importantly, Beacon has informed us that the incident is contained and that there is currently no evidence of misuse or publication of the data that has been potentially impacted.

While there is no specific action you need to take, we would encourage you to continue to exercise vigilance when operating online, including:

  1. Be cautious of suspicious emails, telephone calls, texts, social media messages or correspondence claiming to be from Foothold, Beacon or any other trusted third party.
  2. Check requests by contacting us through the telephone number or email address on our official website, not by using contact details supplied in a suspicious message.
  3. Exercise caution before clicking on links or opening attachments from unexpected communications.
  4. Never disclose passwords, verification codes or financial information in response to unsolicited requests.

The above represents our current understanding. However, as we progress our own investigation, we will continue to provide our community with updates.

We take data security extremely seriously and have taken all steps recommended to us by Beacon and our external experts. This includes notifying the ICO and the Charity Commission in accordance with our legal and regulatory obligations, and engaging external experts to help us assess how this incident may have impacted our community members specifically.

If you have any questions or concerns, please don’t hesitate to contact [email protected].

Our Foothold community is incredibly special, capable of delivering great impact, and we hope that this incident doesn’t affect the way that people feel about it.