Statement on Beacon CRM Possible Data Breach
Statement on Possible Data Breach (Beacon CRM)
6 August 2026 (Last updated: 6 August 2026, 09:00 BST)
EducAid has been informed of a cyber-security incident affecting Beacon CRM, the system we use to manage supporter information. Beacon is used by more than 1,500 charities across the UK.
Beacon has confirmed that an unauthorised third-party gained access to its systems and that information stored within Beacon may have been downloaded. All charities using this system have been advised to assume that the information in Beacon may have been compromised.
EducAid stores minimal information about our supporters. This includes only names, contact details, donation history and Gift Aid eligibility. Payment card details are processed securely through our payment providers, not through Beacon.
As soon as we were informed of the incident, we began working to understand the impact on EducAid. We also notified the Information Commissioner’s Office (ICO) for their advice and guidance. We are continuing to monitor the situation as Beacon’s investigation progresses and updating security of any software linked to Beacon. We are also reviewing our own security practices and access controls.
We wanted to be sure to let you know about this cyber-security incident. At this stage, there is no evidence that information relating to EducAid supporters has been misused and there is no immediate action you need to take.
We encourage you to remain vigilant for unexpected emails, phone calls or messages claiming to be from EducAid or other organisations. We will never contact you unexpectedly to ask for passwords, payment details, or one-time codes or other sensitive personal information.
We understand this news may be concerning. Protecting your information is extremely important to us and a responsibility we take seriously. We will continue to keep you updated if and when we receive additional information.
If you have any questions, please contact us at info@educaid.org.uk.