IMPORTANT NOTICE: Beacon CRM Security Incident

UK-Med has been informed that Beacon CRM, our supporter and member database provider, has experienced a cyber-security incident involving unauthorised access to its systems.
Beacon believes that copies of its database backups may have been downloaded. This means that information held on the platform, including names, email addresses and other personal data, may have been accessed.
UK-Med does not store credit card or payment details on Beacon and therefore they have not been compromised.  
We are making our staff, supporters and members aware of the incident so that they can remain vigilant and as ever, exercise caution about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.
We are very sorry that this has happened and for the inconvenience and concern it might cause.   
Email notification will be sent to both current and former supporters who we are able to contact.
Beacon is investigating the incident with external cyber-security specialists and is working with the relevant authorities. We will provide further updates.
Please see FAQs below or email with specific concerns: dpo@uk-med.org

What exactly happened?

On Wednesday 29th July 2026, Beacon, our external CRM software provider, became aware that they may have experienced a cyber-security incident. They immediately engaged external cyber-security experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of database backups were made. UK-Med was informed by Beacon about the incident on Monday 3rd August. Beacon is operating normally now. There is currently no evidence of data leak to the web.

How did this happen?

Beacon is currently investigating the full circumstances of the incident with external cyber-security specialists, but our current understanding is that a compromised access key was used to gain access to Beacon. This was more sophisticated than a simple compromised username and password.

Why was this data held in Beacon?

Beacon is UK-Med’s customer relationship management (CRM) system, which we use to securely manage relationships and communications with our supporters, members and other contacts. Holding contact information in a CRM enables us to keep people informed about our work, manage donations and memberships, and communicate with individuals in line with their preferences and data protection obligations.

What is UK-Med doing about it?

  • Formally notified the ICO (the UK data regulator) and the Charity Commission of the breach, as well as our Board of Trustees, staff, external supporters, donors and members affected.
  • Reviewed Beacon CRM’s initial response to ensure that sufficient safeguards are in place to continue use of Beacon at this time.
  • Disconnected all APIs, and reestablished those that we can in line with the technical advice.
  • Continue to monitor updates on the incident from Beacon.

How can I protect my data from here?

The UK government has a website with excellent information about things to be aware of after a data breach.  Some of it is about passwords, so I’d just like to reassure you that we do not store passwords on Beacon. You may still want to change your passwords to be on the safe side, and there’s advice on how to create a strong password.  The most useful section is about how to be vigilant with emails and phone calls. Here’s the link: Data breach guidance for individuals