Beacon CRM Data Security Incident

Current Information

Information About the Beacon CRM Incident

This page is for anyone whose details are held by SCA UK in Beacon, the third-party system we use to manage information about our members (Friends Of), supporters, donors, event attendees and other contacts.

Last updated: 12 August 2026

Beacon, the third-party system SCA UK uses to hold information about our members, supporters, donors and contacts, has suffered a cyber-security incident. An unauthorised third party gained access to Beacon’s systems and exported all of the data held in its database. This happened at Beacon, not at SCA UK.

Beacon does not hold any bank or card details. SCA UK’s payments are handled separately by companies such as PayPal, Stripe, and GoCardless, none of which are affected by this incident. You do not need to cancel a Direct Debit, change a card, or contact your bank.

There is no action you need to take right now. There are some things worth watching out for, and we have set those out below.

Beacon is used by more than 1,000 UK charities, and this incident is not specific to SCA UK. Beacon has brought in external cyber-security specialists and its investigation is continuing.

What Happened

Beacon became aware on 29 July 2026 that it may have experienced a cyber-security incident. On 12 August 2026 it published the findings of its investigation.

Beacon says the probable cause was a compromised Amazon Web Services access key, which it believes may have been exposed in publicly accessible JavaScript files on its own site. Using that key, an unauthorised third party accessed Beacon’s systems in the early hours of 27 July 2026. The earliest activity Beacon has identified so far began at about 1.20am UTC and lasted around an hour and a half. Beacon’s assessment is that the attacker exported all of the data held in its database. Beacon’s data is encrypted where it is stored, but because the attacker had valid credentials, that encryption did not prevent the data being read.

Beacon has told us that its monitoring has so far found no indication that any of the information has been published, disclosed or misused, and that no ransom has been demanded. It has reported the incident to the Information Commissioner’s Office and to Action Fraud.

Beacon informed SCA UK on the afternoon of 3 August 2026. It has advised all its customers to assume that the information stored in their accounts, including attachments, may have been involved. Beacon has said there is currently no evidence that the information has been published or misused, and no ransom has been demanded.

We know that this may feel like a long time to have waited. Beacon became aware on 29 July but did not tell us until the afternoon of 3 August. We have used the days since to secure our account, establish what information was actually involved, take advice, and report the incident to the Information Commissioner’s Office and the Charity Commission. We would rather have told you something accurate than something fast.

What Information May Be Involved

If you have never donated to SCA UK, never been in touch with us, and are not a member (Friend Of) or a volunteer, your information is not held in this system.

What we hold varies from person to person, depending on how you have been involved with SCA UK. It may include:

  • your name;
  • your email address, postal address and telephone number;
  • records of donations you have made, including amounts and dates, and donations made through JustGiving;
  • your Gift Aid status, if you have made a declaration;
  • membership, volunteering, event or meet-up information;
  • copies of emails between you and SCA UK, which are kept on your record; and
  • in a small number of cases, information about your health that you have shared with us.

Not all of these will apply to everyone. Beacon’s assessment is that all of the data in its database was exported, so if your details were in our Beacon account before 28 July 2026 you should assume they were included. We can’t even confirm that any SCA UK records have been downloaded or viewed, but we have chosen to inform you out of an abundance of caution.

Being Straight With You

We want to be honest about the part of this that may matter most to you. Because of what SCA UK is, appearing on our list may in itself suggest that you or someone close to you has had a cardiac arrest. That is private information, and not everyone has shared it widely.

Beacon has seen no evidence that any of this information has been published anywhere, and criminals in incidents like this are usually looking for money rather than reading individual records. But we would rather tell you plainly than reassure you further than we honestly can.

What SCA UK Has Done

Protecting the information you have trusted us with matters a great deal to a charity like ours. Since being notified, we have:

  • disconnected and reconnected every system linked to Beacon, and reset all our passwords;
  • followed Beacon’s immediate security recommendations;
  • reviewed the information held in our account and assessed the risks to the people it belongs to;
  • reported the incident to the Information Commissioner’s Office and to the Charity Commission;
  • briefed our trustees, who are being kept updated;
  • followed the information and community activity of other Beacon users closely, so that we benefit from what the wider charity sector is learning about this incident; and
  • asked Beacon for specific answers about exactly what was taken, which we are continuing to press for.

We will also contact directly anyone we believe may be more affected than most.

What We Suggest You Do

We are not aware of any misuse of anyone’s information. As a sensible precaution, though, we would suggest that you:

  • are wary of unexpected emails, telephone calls, text messages or social media messages, particularly any that use your name and appear to know about your connection to SCA UK, or that claim to be from Beacon;
  • do not click links or open attachments in messages you were not expecting;
  • never give out a password, a verification code or bank details in response to a message that came to you;
  • check that your email password is strong and not used anywhere else; and
  • are careful with claims companies. You may be approached by firms offering to pursue compensation on your behalf. That is entirely your decision, but check who you are dealing with before giving anyone your personal or financial details.

SCA UK will never contact you unexpectedly to ask for payment, bank details or a password. If someone does, claiming to be us, it is not us. If you are unsure about any message, get in touch using contact details you already have for SCA UK.


How to Spot a Suspicious Message

A scam message can look convincing, and it may contain details that are perfectly correct. Take extra care if you notice any of the following.

Unexpected contact. The message turns up out of the blue and asks you to reply, make a payment, confirm an account or provide personal information.

Pressure or urgency. You are told to act immediately, warned that something bad will happen, or discouraged from checking with anyone else.

An unusual sender address. The name displayed may say Sudden Cardiac Arrest UK, but the actual email address is unfamiliar, misspelt, or has nothing to do with us.

Links and attachments. The message asks you to follow a link, download a file or open an attachment that you were not expecting.

Requests for sensitive information. The sender asks for a password, bank details, a card number, a security code or other private information.

Information that sounds familiar. A scammer may mention a real donation, a real event or our name to make a message appear genuine. Correct details do not always mean a message is safe.

What to Do

  1. Stop and check. Do not respond, click a link or open an attachment.
  2. Contact us separately. Type our website address (you can use the short version: scauk.org) into your browser yourself, or use contact details you already know are genuine.
  3. Tell SCA UK. Send suspicious messages claiming to be from us to [email protected]. It helps us warn everyone else quickly.
  4. Report suspicious emails and texts. Forward scam emails to [email protected] and scam text messages to 7726, which is free from any UK mobile.
  5. Act quickly if money is involved. If you have shared bank details or lost money, contact your bank immediately. In England, Wales and Northern Ireland, report fraud at reportfraud.police.uk. In Scotland, call Police Scotland on 101.

If This Has Unsettled You

Living with the after-effects of a cardiac arrest is hard enough, and news like this does not help. If you would like to talk to someone who understands, the SCA UK community is here.

Frequently Asked Questions

Select a question below to read the answer.

Why have I received an email from SCA UK about a data breach?

Because your email address is attached to one or more records SCA UK holds in Beacon, the system affected by this incident. That might be because you donated to us, including through JustGiving, Enthuse or because you are a Friend Of, a volunteer, have come to a meet-up, or have been in touch with us at some point.

If it has been a while and you had forgotten about us, that is completely understandable, and this is the reason we still had your details.

Does this mean my information or email was definitely taken?

Not necessarily. What Beacon has confirmed is that copies of its database backups were made, and that the available evidence suggests those copies were likely downloaded.

Neither Beacon nor SCA UK can tell which individual records inside those copies were actually opened or read. Because of that, Beacon has advised all its customers to assume the information was involved, and that is the assumption we are working on.

Why can you not tell me exactly what was taken about me?

Because of the way this attack worked. Whole database backups were copied, rather than particular records being opened one at a time, so there is no list of who was affected and who was not.

We have asked Beacon for more specific answers and we are continuing to press for them. If we learn anything that changes what we have told you, we will say so.

Was my bank or card information involved?

No. SCA UK does not hold bank or card details in Beacon.

Our payments are handled separately by companies such as PayPal, Stripe and GoCardless, and none of those is affected by this incident. You do not need to cancel a Direct Debit, change a card, or contact your bank because of this.

What Beacon does hold is a record that a donation was made, including the amount and the date. That is not the same as your payment details.

Does this mean people know I had a cardiac arrest?

We have to be honest with you: possibly.

Because of what SCA UK is, being on our list may in itself suggest that you or someone close to you has had a cardiac arrest. For some people, that is private, and not something they have shared widely.

Beacon has seen no evidence that any of the information has been published anywhere, and criminals in incidents like this are generally looking for money rather than reading individual records. But we would rather tell you plainly than offer you more reassurance than we can honestly stand behind.

Am I at risk of fraud?

The realistic risk is convincing scam messages rather than direct financial fraud, because no payment details were held in the affected system.

Someone holding contact and donation records could write a message that looks genuine, using your real name and mentioning a real donation or event. Be cautious about unexpected emails, texts or phone calls, particularly any asking you to click a link, log in somewhere, or make a payment.

SCA UK will never contact you unexpectedly to ask for payment, bank details or a password. If someone does, claiming to be us, it is not us. If you are unsure about a message, contact us using details you already have rather than anything supplied in the message itself.

Do I need to do anything right now?

There is no immediate action you need to take, and nothing to cancel or change with your bank.

It is worth staying alert to unexpected messages for the next few weeks, and if you use the same password anywhere else that you have used with us, change it. Never feel rushed by a message that puts you under pressure to act quickly.

Why has it taken until now to tell me?

We know this may feel like a long time to have waited, so it is worth setting out the dates plainly.

Beacon became aware on 29 July 2026 that it may have experienced a cyber-security incident. It did not inform SCA UK until the afternoon of 3 August.

Since then, we have secured our account and reset our passwords, worked through what information was actually involved and who it belongs to, taken advice, and reported the incident to the Information Commissioner’s Office and the Charity Commission. We have also been pressing Beacon for specific answers about what was taken, which we are still waiting on.

We could have written to you sooner with very little in it. We would rather have told you something accurate than something fast.

Has SCA UK done something wrong?

The break-in happened at Beacon, not at SCA UK. Beacon is an established system used by more than 1,000 UK charities, and it was chosen for that reason.

That said, the information is ours to look after, and being let down by a supplier does not change our responsibility to the people it belongs to. So we are reviewing what we hold, how long we keep it, and how we assess the security of the organisations we rely on.

Will SCA UK keep using Beacon?

Our immediate priority is looking after the people affected by this incident.

Our trustees will review our systems and our suppliers once the immediate response is complete, and that review will include Beacon.

Can you delete my information?

Yes. Tell us and we will.

Two things worth knowing. Deleting your record now will not remove it from the copy that was already taken, so it does not undo this incident. We may also need to keep a minimal note of your request so we can honour it.

If you have made a Gift Aid declaration, we are required to keep certain records for HMRC. If that applies to you, we will explain exactly what we have to keep and for how long.

Will this page be updated?

Yes. We will update this page whenever Beacon gives us anything significant to share, and we will change the date at the top each time we do.

It is worth checking back here rather than waiting to hear from us, though we will contact people directly if we learn something that materially changes what we have told you.

Further Information

Beacon has published its own updates and answers on its incident FAQs page. The Information Commissioner’s Office has advice for people who have been told about a data breach, and the National Cyber Security Centre has guidance on recognising and reporting phishing emails, texts and calls.

Questions or Concerns

If you have a question about this incident, or you receive a suspicious message claiming to be from SCA UK, please contact us at [email protected]. We are a very small team, so please bear with us — we will come back to you.

We are sorry this has happened, and we are grateful for your patience while we work through it.

We will update this page whenever Beacon gives us anything significant to share, and we will change the date at the top when we do.

Item added to cart.
0 items - £0.00
Sudden Cardiac Arrest UK
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.