What exactly happened?
On Wednesday 29th July 2026, Beacon, our external CRM software provider, became aware that they may have experienced a cyber-security incident. They immediately engaged external cyber-security experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of database backups were made. UK-Med was informed by Beacon about the incident on Monday 3rd August. Beacon is operating normally now. There is currently no evidence of data leak to the web.
How did this happen?
Beacon is currently investigating the full circumstances of the incident with external cyber-security specialists, but our current understanding is that a compromised access key was used to gain access to Beacon. This was more sophisticated than a simple compromised username and password.
Why was this data held in Beacon?
Beacon is UK-Med’s customer relationship management (CRM) system, which we use to securely manage relationships and communications with our supporters, members and other contacts. Holding contact information in a CRM enables us to keep people informed about our work, manage donations and memberships, and communicate with individuals in line with their preferences and data protection obligations.
What is UK-Med doing about it?
- Formally notified the ICO (the UK data regulator) and the Charity Commission of the breach, as well as our Board of Trustees, staff, external supporters, donors and members affected.
- Reviewed Beacon CRM’s initial response to ensure that sufficient safeguards are in place to continue use of Beacon at this time.
- Disconnected all APIs, and reestablished those that we can in line with the technical advice.
- Continue to monitor updates on the incident from Beacon.
How can I protect my data from here?
The UK government has a website with excellent information about things to be aware of after a data breach. Some of it is about passwords, so I’d just like to reassure you that we do not store passwords on Beacon. You may still want to change your passwords to be on the safe side, and there’s advice on how to create a strong password. The most useful section is about how to be vigilant with emails and phone calls. Here’s the link: Data breach guidance for individuals