Data Security Incident Notification – Beacon CRM

Beacon

On 29th July 2026, Beacon, the customer relationship management (CRM) system used by Stripey Stork to store information about our supporters, volunteers and donors, were involved in a cyber-security incident.

Beacon is a well-established CRM platform that is widely used across the charity sector. Beacon informed us on 3rd August 2026 that it had experienced a cyber-security incident in which unauthorised access may have been gained to copies of customer databases. At this stage, there is no evidence that any Stripey Stork data has been published or misused, but Beacon believes copies of some encrypted customer databases were likely downloaded, and this may therefore include the Stripey Stork data.

The information we hold in Beacon is limited to contact details (such as your name, email address, opt-in preferences and, for some supporters, a postal address) together with records of any donations or support you have given. We do not hold or store any other sensitive personal information within Beacon.

Beacon has advised that although data is stored in an encrypted state, decryption remains a potential risk but that currently, there is no evidence of the data appearing on the dark web, and they tell us that they have not received any ransom demand. Beacon is taking this incident extremely seriously. They say they have implemented immediate measures to secure its systems and prevent any further unauthorised access. In addition they are now:

  • Conducting a thorough forensic investigation with their external cyber-security specialists to understand exactly what happened;
  • Working with law enforcement and relevant regulators as required;
  • Conducting online monitoring, as is standard practice in these kinds of incidents. So far, they tell us they haven’t seen anything of concern;
  • Completing precautionary security measures.

As soon as we were notified, we immediately took all the security steps recommended by Beacon, including reviewing and securing access to our systems. We have also voluntarily reported the incident to the Information Commissioner’s Office (ICO) and the Charity Commission and will continue to follow their guidance as the investigation progresses.

Currently, there is no action you need to take. However, as a sensible precaution, please remain vigilant for any unexpected or suspicious emails or other communications claiming to be from Stripey Stork. We will never ask you to provide passwords, bank details or other sensitive information by email. If you have any other questions or concerns about this matter, please contact Nicola Dawes.

We take the security of personal information, and the trust our supporters place in us, extremely seriously. We wanted to let you know about this incident as soon as possible and will provide further updates if anything changes.

Thank you for your continued support and understanding.

Share this news article...

Facebook
LinkedIn
X
Pinterest
Email

More news...