Several charities have reported a data breach connected to Beacon CRM, a software provider used to manage donor information and fundraising activities. The incident, disclosed by Beacon CRM on August 7, involved unauthorized access through a compromised access key, enabling a third party to copy and likely download database backups containing sensitive information.

Beacon CRM stated that while donor data was accessed, there is no indication that payment card details were compromised in the breach. The affected organizations potentially include a range of well-known charities such as Mind, Teenage Cancer Trust, Age UK London, English National Ballet, Girlguiding, Sands, and the Molly Rose Foundation.

The company is currently investigating the full scope of the breach and working with affected clients to mitigate potential risks. It has also informed relevant authorities but did not provide a detailed timeline of the incident or specific security measures being implemented to prevent future occurrences.

The breach highlights ongoing concerns about cybersecurity vulnerabilities within the nonprofit sector, where reliance on third-party software services for donor management is common. Charities impacted are reviewing their own security protocols and communicating with their supporters to address any questions or concerns related to the incident.