
CIOF partners with monthly UK public tracker to understand fundraising activity
September 16, 2026
Swiss foundations’ assets grow by 24% in five years
September 16, 2026A cloud-based data platform used by more than 1,000 charities in the UK and Ireland fell victim to a cyber attack in July, compromising the personal data of a significant number of donors.
Beacon informed its customers of the attack on 4 August, which it said started in the early hours of the morning on 27 July. Beacon immediately reported the incident to the Information Commissioner’s Office and the authorities, bringing in expert support to help it conduct an investigation.
While the investigation confirmed that a copy of the database holding all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor, it found no evidence that any bank card details had been compromised, or that the data stolen had been “published, disclosed, or otherwise misused”.
The most recent update posted on its website (3 September) concluded the investigation, and said that while the threat actor had not been engaged with, they had contacted Beacon once towards the conclusion of the investigation to indicate they would be deleting any data they have exfiltrated and that no copy would be retained, sold, or shared. Beacon adds that dark web monitoring has found no mention of this incident or data related to it online, and that there is no evidence this was a targeted attack on Beacon, or any specific Beacon customer. Everything learned has been shared with law enforcement.
According to Beacon, the probable root cause of the incident was a compromised AWS access key. These are credentials used to allow the Beacon application to communicate securely with Amazon Web Services, its primary cloud hosting provider. Beacon’s understanding is that this access key was inadvertently exposed in its application code and subsequently used to gain unauthorised access to the organisation’s AWS environment.
The vulnerability that enabled this to happen has since been fixed, and measures implemented to ensure it cannot happen again. These are listed in Beacon’s report, accessible here.
During its investigation, Beacon published an Incident FAQs and Incident Guidance page on its website, providing advice and explanations of the situation and what customers should do next. These also clarified that Beacon was still “operating normally” and that charities could continue to collect payments through it. In a statement to Fundraising Europe on 1 September, Beacon said:
“Since containing the initial incident, we have not identified or observed any ongoing unauthorised access to Beacon’s systems. Our customers continue to access our platform and services as normal.”
Beacon’s website says it is used by more than 1,000 charities. The company is based in London and most client case studies on its website are charities based in the UK, with at least two from the Republic of Ireland.
Reports to regulator & maintaining supporter trust
Following the incident, Beacon and the Charity Commission for England and Wales (CCEW) advised that charities should consider their reporting obligations, such as whether they needed to report the incident to the CCEW, to the Information Commissioner’s Office (ICO) or other regulators. CCEW’s statement also said:
“We know many Beacon customers have moved promptly to inform their supporters about this incident. Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work.”
The Fundraising Regulator also said that all charities impacted needed to submit a report through its website.
The CCEW provides guidance on how to report a serious incident and how to protect charities from cyber crime and fraud.



