FAQ

Why has it taken until now to tell me about the Beacon incident?

We know this may feel like a long time to have waited, so it is worth setting out the dates plainly.

Beacon became aware on 29 July 2026 that it may have experienced a cyber-security incident. It did not inform SCA UK until the afternoon of 3 August.

Since then we have secured our account and reset our passwords, worked through what information was actually involved and who it belongs to, taken advice, and reported the incident to the Information Commissioner’s Office and the Charity Commission. We have also been pressing Beacon for specific answers about what was taken, which we are still waiting on.

We could have written to you sooner with very little in it. We would rather have told you something accurate than something fast.

Category: Data Security Incident

Will this page be updated?

Yes. We will update this page whenever Beacon gives us anything significant to share, and we will change the date at the top each time we do.

It is worth checking back here rather than waiting to hear from us, though we will contact people directly if we learn something that materially changes what we have told you.

Category: Data Security Incident

Can you delete my information?

Yes. Tell us and we will.

Two things worth knowing. Deleting your record now will not remove it from the copy that was already taken, so it does not undo this incident. And we may need to keep a minimal note of your request so that we can honour it.

If you have made a Gift Aid declaration, we are required to keep certain records for HMRC. If that applies to you, we will explain exactly what we have to keep and for how long.

Category: Data Security Incident

Will SCA UK keep using Beacon?

Our immediate priority is looking after the people whose information was involved, and getting clearer answers from Beacon about what happened.

Our trustees will review our systems and suppliers once that immediate work is done. We would rather make that decision properly than announce something in the first week.

Category: Data Security Incident

Has SCA UK done something wrong?

The break-in happened at Beacon, not at SCA UK. Beacon is an established system used by more than 1,000 UK charities, and it was chosen for that reason.

That said, the information is ours to look after, and being let down by a supplier does not change our responsibility to the people it belongs to. So we are reviewing what we hold, how long we keep it, and how we assess the security of the organisations we rely on.

Category: Data Security Incident

Do I need to do anything right now?

There is no immediate action you need to take, and nothing to cancel.

It is worth staying alert to unexpected emails, telephone calls, text messages or social media messages for the next while, particularly any that seem to know about your connection to SCA UK. If you use the same password anywhere else that you have used with us, it is a good moment to change it.

Beyond that, please do not feel rushed by any message that creates a sense of urgency. That pressure is itself one of the clearest signs of a scam.

Category: Data Security Incident

Am I at risk of fraud after the Beacon data breach?

The realistic risk is convincing scam messages rather than direct financial fraud, because no payment details were held in the affected system.

Someone holding contact and donation records could write a message that looks genuine, using your real name and mentioning a real donation or event. Be cautious about unexpected emails, texts or phone calls, particularly any asking you to click a link, log in somewhere, or make a payment.

SCA UK will never contact you unexpectedly to ask for payment, bank details or a password. If someone does, claiming to be us, it is not us. If you are unsure about a message, contact us using details you already have rather than anything supplied in the message itself.

Category: Data Security Incident

Does this mean people know I had a cardiac arrest?

We have to be honest with you: possibly.

Because of what SCA UK is, being on our list may in itself suggest that you or someone close to you has had a cardiac arrest. For some people that is private, and not something they have shared widely.

Beacon has seen no evidence that any of the information has been published anywhere, and criminals in incidents like this are generally looking for money rather than reading individual records. But we would rather tell you plainly than offer you more reassurance than we can honestly stand behind.

Category: Data Security Incident

Was my bank or card information involved in the Beacon incident?

No. SCA UK does not hold bank or card details in Beacon.

Our payments are handled separately by companies such as PayPal, Stripe and GoCardless, and none of those is affected by this incident. You do not need to cancel a Direct Debit, change a card, or contact your bank because of this.

What Beacon does hold is a record that a donation was made, including the amount and the date. That is not the same as your payment details.

Category: Data Security Incident

Why can you not tell me exactly what was taken about me?

Because of the way this attack worked. Whole database backups were copied, rather than particular records being opened one at a time, so there is no list showing who was affected and who was not.

We have asked Beacon for more specific answers about exactly which data was involved, and we are continuing to press them on it. If we learn anything that changes what we have told you, we will say so on this page and contact people directly where we need to.

Category: Data Security Incident

Does this mean my information was definitely taken?

Not necessarily. What Beacon has confirmed is that copies of its database backups were made, and that the available evidence suggests those copies were likely downloaded.

Neither Beacon nor SCA UK can tell which individual records inside those copies were actually opened or read. Because of that, Beacon has advised all its customers to assume the information was involved, and that is the assumption we are working on.

Category: Data Security Incident

Why have I received an email from SCA UK about a data breach?

Because your email address is attached to one or more records SCA UK holds in Beacon, the third-party system affected by this incident.

That might be because you donated to us, including through JustGiving, which passes donor details on to the charity. It might be because you are a member or a volunteer, because you have come to a meet-up or an event, or because you have been in touch with us at some point.

If it has been a while and you had forgotten about us, that is completely understandable, and it is simply why we still had your details on file.

Category: Data Security Incident
Item added to cart.
0 items - £0.00
Sudden Cardiac Arrest UK
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.