Beacon CRM Incident – Final Update

An update on the Beacon CRM cyber security incident reported in August, following the conclusion of Beacon’s investigation and the Society’s own review.


In August, I wrote to members and supporters to inform you of a cyber security incident involving Beacon CRM, the third-party customer relationship management system used by the SAHGB to manage information about our members, supporters, event attendees and contacts.

Following notification of the incident, the Society took appropriate steps to assess and respond to the matter. This included reporting the personal data breach to the Information Commissioner’s Office (ICO), considering the guidance and correspondence issued by the Charity Commission, and undertaking an internal review.

Beacon has now concluded its investigation into the incident and published its final report. The report explains what happened, the steps Beacon has taken in response and the additional measures it has introduced following the incident. Beacon has also obtained independent external attestation of the work undertaken.

The ICO acknowledged the Society’s breach report on 6 August 2026. It confirmed that it was aware of the wider incident affecting Beacon customers, that our report had been logged and that it did not plan to contact the Society further. The ICO concluded its correspondence by stating: “We now consider the matter to be closed.”

The ICO noted that it may make further enquiries if new information arises, including if it receives complaints relating to the breach.

The Charity Commission advised charities affected by the Beacon incident that they do not need to submit a Serious Incident Report simply because they are Beacon customers or because their data may have been held on Beacon systems. It advised that a report would be expected if a charity became the focus of a specific or targeted cyber-attack, fraud, data misuse or another incident arising from the breach, and that incident met the Commission’s serious incident reporting threshold.

The Commission also advised trustees to continue considering the possible impact on their charity and to take reasonable steps to manage any associated risks. The Society has done so as part of its review and has received no evidence that the Beacon incident has resulted in fraud, misuse of personal information or any other incident affecting the SAHGB that would meet the Charity Commission’s serious incident reporting threshold.

As explained in our original notification, the SAHGB does not store payment card or bank account details within Beacon, and Beacon found no evidence that payment or financial information had been compromised. Data provided to the Society concerning protected characteristics, such as disability or ethnicity, was not affected.

We have received no information since our August notification that changes the advice given at that time. Beacon has now completed its investigation, the ICO has closed the Society’s breach report, and the Society has completed its own review. On that basis, the Society considers this matter closed.

As a general precaution, we nevertheless encourage members and supporters to remain vigilant about unexpected communications purporting to come from the Society. Please be cautious if you receive unexpected emails, telephone calls or text messages asking for personal information or encouraging you to click on links or open attachments. Emails from the SAHGB should come from an address ending in @sahgb.org.uk.

The SAHGB will never ask you to disclose your password or security codes by telephone or email. If you are ever unsure whether a communication is genuine, please contact us directly using info@sahgb.org.uk.

Thank you for your patience while this matter was being investigated.


All updates:

Edward Walker

Digital & Communications Manager

Next
Next

Towards a New Cathedral