We want to let our community know about a data security incident that has affected Beacon, the customer relationship management (CRM) system we use to help manage our supporter, volunteer, and service user information.
We know that news like this can be worrying, so we wanted to keep you informed about what happened, what we know, and what we’re doing about it.
What happened:
On Wednesday 29 July 2026, Beacon identified that an unauthorised third party had gained access to its systems. Beacon notified Let’s Talk About Loss of the incident on Monday 3 August 2026.
Beacon’s investigation, supported by external cyber-security specialists, has since identified the likely cause as a compromised AWS access key. The earliest malicious activity identified by Beacon took place on 27 July 2026.
When we were first notified, Beacon was unable to establish which individual records had been downloaded and advised organisations to take a precautionary approach and treat data held within Beacon as potentially affected. In line with this advice, we proceeded from the outset on the precautionary basis that all information held by Let’s Talk About Loss within Beacon may have been accessed or downloaded.
Beacon has now provided a further update following additional forensic investigation. Based on its analysis of the activity and the volume of data transferred, Beacon’s current assessment is that the unauthorised third party exported all data contained within the affected database, including attachment files.
Beacon has also confirmed that, although the data was encrypted while stored within its AWS environment, the credentials used by the unauthorised third party meant that data downloaded through AWS would have been decrypted and therefore readable. This latest information provides stronger evidence for the precautionary position we had already taken.
This incident was not specific to Let’s Talk About Loss. Beacon provides CRM services to many charities and other organisations, and the incident has affected data held by multiple Beacon customers.
What information may have been accessed:
The information held by Let’s Talk About Loss in Beacon varies from person to person depending on how you have interacted with us and what information you have provided.
Information held within our Beacon account may have included:
- Names and contact details, such as email addresses, postal addresses and telephone numbers
- Dates of birth, where provided
- Emergency contact information
- Information about your bereavement, where you provided this to us
- Information relating to your involvement with Let’s Talk About Loss, such as Meet Up preferences or volunteer information
- Some information about protected characteristics or other sensitive information you chose to provide to us, such as gender identity, religious identity or access requirements
Not every category listed above will apply to every person whose information was held in Beacon.
Beacon has advised that from their online monitoring there is currently no indication that the data associated with the incident has been published, disclosed, or otherwise misused.
What we are doing about it:
As soon as we were notified, we began our own response, including:
- Reviewing exactly what data we hold within Beacon and who it relates to
- Assessing the level of risk to the people affected, in line with our obligations under UK GDPR
- Informing affected individuals
- Reporting the incident to the Information Commissioner’s Office. Our Case Reference No. is IC-551161-D3K7
- Reporting a Serious Incident to the Charity Commission – our Incident Reference No. is 927123
- Informing our Board of Trustees
- Reviewing our own internal processes and our arrangements with third-party data processors
- Continuing to monitor Beacon’s investigation and reviewing new information as it becomes available
The ICO has confirmed to us that they are aware of the wider incident involving Beacon CRM and its impact on multiple organisations
What Beacon has done:
Beacon has told us that it has:
- Remediated the vulnerability believed to have enabled the unauthorised access
- Reset credentials for services and accounts integrated with AWS
- Introduced additional security monitoring across its environment
- Implemented continuous 24/7 monitoring for suspicious activity
- Continued to work with external cyber-security specialists on its investigation
Beacon has advised that, since containing the initial incident and remediating the likely cause, it has identified no suspicious activity or ongoing unauthorised access to its systems.
Beacon’s investigation remains ongoing, and it expects to provide a final summary of its findings in the coming weeks.
What this means for you:
As a sensible precaution, we’d encourage everyone in our community to:
- Be cautious of unexpected emails, texts or calls, especially communications asking you to click a link, provide personal information or take urgent action
- Never share verification codes, passwords or banking details in response to an unsolicited request
- If a communication appears to come from an organisation you recognise but you are unsure whether it is genuine, contact that organisation independently using contact details from its official website
- Contact us directly if you receive anything suspicious that you believe may be connected with this incident
If you have questions or concerns about the incident, or would like further information about the information Let’s Talk About Loss held about you in Beacon, please contact Catrin at lead@letstalkaboutloss.org
Our commitment to you:
Let’s Talk About Loss takes our responsibility to protect the information entrusted to us extremely seriously. We are sorry that this has happened, and for any concern it may cause.
We will continue to monitor Beacon’s investigation and review our own arrangements in light of what we learn. We will update this statement again if further information materially changes our understanding of the incident or the action affected individuals should take.
This statement will be updated as we learn more. Last updated 14.08.2026