Skip to main content
News

Beacon Cyber Security Incident *updated September*

By August 7, 2026September 3rd, 2026No Comments

Updated 3rd September 2026

Dear SIFA Supporter,

We have today received the final report on the Beacon Cyber Security Incident that occurred on the 3rd of August.

The report goes into detail of the incident and the measures that Beacon have been put in place to mitigate the risks of such an incident happening again, but I have highlighted below the section that I think will bring the most comfort to our supporters.

“Since containing the initial incident and eradicating the likely root cause, no suspicious activity or ongoing unauthorised access to Beacon’s AWS environment or engineer endpoints have been identified. No methods of persistence used by the threat actor to maintain access to the AWS environment have been identified.

Given the identification of a probable root cause, its eradication, and following a review by cyber-security experts that did not identify any other vulnerabilities as a result of this incident, Beacon’s engineering team are confident that the incident is resolved.”

You can download and read Beacon’s full report here.

I hope that this brings some relief to those that were concerned about the incident.

Thank you for your understanding throughout what has been a challenging time and thank you again for your continued support.

Robb Sheppard

Head of Fundraising and Communications

 

Updated 27th August 2026

Dear SIFA Supporter,

Following on from our previous communication on the 7th August, we are writing to provide you with an update on the cyber security breach that has affected Beacon CRM (Customer Relationship Management) system, which manages the data of many charities and organisations, including SIFA Fireside.

We have since received a further update from Beacon published on 12th August, stating that a copy of the database, including attachment files, was made and likely downloaded in a readable format. There is currently no evidence that information associated with the incident has been published, disclosed or otherwise misused.

Following this update, we have reviewed all attachments within Beacon and have identified that we do hold some additional records containing bank account and/or sort code numbers. This has affected 22 of our supporters who have all been contacted by letter with further information.

We have now reviewed our internal processes further and have confirmed the minimum data we must hold to meet our regulatory and audit requirements. We have also consulted with the Information Commissioner’s Office (ICO) and have updated our own report accordingly.

Incidents of this nature can sometimes lead to an increase in phishing attempts which, unfortunately, you could be more vulnerable to. As a precaution, we recommend being vigilant if you receive any unexpected emails, text messages or phone calls as well as looking out for any unusual activity.

Beacon themselves have reported the incident to the Information Commissioner’s Office (ICO) and are continuing to investigate the situation. You can find their latest statement on the incident here. If you would like to reach out to Beacon directly with any queries, you can do so at incident@beaconcrm.org.

We understand this may cause concern but want to reiterate that we always have and always will do our best to ensure that our supporters’ privacy and security is of the highest priority. Your support and generosity means a lot to all of us at SIFA Fireside and we are still deeply saddened by the situation. If you would like to discuss this further, please reach out to us at fundraising@sifafireside.co.uk.

Thank you so much for your ongoing support and for your understanding.

Robb Sheppard

Head of Fundraising and Communications

 

Updated August 7th 2026

Dear SIFA Supporter,

We are getting in touch to tell you about a recent cyber security incident that has affected Beacon, the organisation that manages SIFA Fireside’s, and many other charity’s supporter data.

From the information that Beacon has provided us with, there is the possibility that basic information such as full names, postal and email addresses and dates of birth have been accessed by a third party.

Here at SIFA Fireside, we do not hold our supporters’ bank or payment details but as Beacon imports data from third party sites, such as Just Giving, there is the possibility that this information may have also been breached. The nature of the data that has been accessed as part of the data breach has neither been confirmed nor denied by Beacon at this point.

Beacon themselves have reported the incident to the Information Commissioner’s Office (ICO) and are continuing to investigate the situation. In turn, SIFA Fireside promptly submitted the report to the ICO within the 72-hour window and are carrying out our own investigation into the incident.

We have also reviewed our own internal processes and will continue to consider whether we remain long-term Beacon customers as we get more information.
SIFA Fireside literally couldn’t do what we do without our supporters and we are deeply concerned about this situation. We always have and always will do our best to ensure that our supporters’ privacy and security is of the highest priority. We have shared all of the information that we currently have and will strive to update you as soon as we receive an update from Beacon.

Thank you so much for your ongoing support and for your understanding.

Robb Sheppard
Head of Fundraising and Communications

 

Robb Sheppard