Guidance on Beacon Cyber Security Incident
Notification of a cyber-security incident involving Beacon CRM, a widely used customer relationship management (CRM) system. Beacon is used by over 1,000 charities and non-profit organisations across the UK to securely manage supporter and membership information and is used by RDA UK.
The incident occurred within Beacon CRM’s systems and not within RDA UK’s own IT systems or network. Beacon has informed us that it experienced a cyber-security incident involving unauthorised access to its platform. According to Beacon’s investigation, copies of database backups were likely downloaded by an unauthorised third party.
Individuals whose information was held within Beacon CRM prior to 27 July 2026 may have been affected, RDA UK have notified those individual by email where addresses are held. At this time, there is no evidence that the information has been publicly released or misused, and Beacon has confirmed there has been no ransom demand.
The personal information held in Beacon was limited to what had previously been provided. This will vary depending on the engagement had with RDA, and may include:
• Name
• Email address
• Postal address
• Telephone number
• Date of birth
• Emergency contact details
Please be assured that this list only suggests the type of information we may hold. It does not mean that all of these details were held for every individual. The information recorded varies from person to person and reflects the nature of the specific engagement with RDA UK.
What has happened?
Beacon became aware of the incident on 29 July 2026 and immediately engaged independent cyber-security specialists to investigate and secure its systems. Beacon notified us of the incident on 3 August 2026 after establishing that copies of customer database backups were likely to have been taken.
As the organisation responsible for personal information, we are publishing this notification to ensure that individuals are aware of the incident and can take any appropriate precautions.
What should you do?
Although there is currently no evidence that information has been misused, we recommend that you:
• Be cautious of unexpected emails, text messages or telephone calls claiming to be from our organisation or other trusted organisations.
• Do not click on links or open attachments in suspicious messages.
• Verify the sender’s email address carefully before responding to any communication requesting personal or financial information.
• Remain vigilant for phishing attempts or identity fraud.
• If you receive a message claiming to be from us that comes from a different address or appears suspicious, please do not respond or click any links.
What are we doing?
Whilst this incident occurred within Beacon’s systems and not within our own IT environment, we take our responsibility for protecting personal information extremely seriously.
We are working closely with Beacon as they continue their forensic investigation and have reviewed the actions they have taken to secure their systems. We have also assessed our own obligations under UK data protection legislation and have reported this incident to the Information Commissioner’s Office where required.
We will continue to monitor updates from Beacon and will inform you if any new information comes to light that affects personal data.
We appreciate that news of this nature may be concerning and sincerely regret that information may have been affected by a security incident involving one of our software providers. If you have any questions there is some general information available on The National Cyber Security Centre website or if you have a specific question, please contact us at dpo@rda.org.uk or in writing to DPO, Lowlands Equestrian Centre, Shrewley, Warwickshire, CV35 7AX.
Thank you for your understanding.
Kind regards,
RDA UK




