Data Security Incident Notification – Beacon CRM
Last updated: 06/08/26
On Monday 3 August, we were advised by Beacon CRM – the platform that hosts our supporter database - that they had a cyber-security incident late last week that involved unauthorised access to Beacon's systems.
It is not yet confirmed whether Gendered Intelligence’s data is affected and to what extent, but according to Beacon copies of Beacon's database backups - which hold data for all the charities that use the system - have been made and 'likely downloaded'.
Although data is stored in an encrypted state, decryption remains a potential risk. Currently, there is no evidence of the data appearing on the dark web.
How your data may be affected
If you have previously supported Gendered Intelligence by donating, campaigning, joining our therapists & counsellors network, or attending on of our training sessions, or you are a contact at an organisation that has given us a grant or worked with us in the past, we may hold your details on our Beacon system.
We only store basic information on Beacon such as your name, contact details, or organisation. We also store details such as donations you have made to us in the past or events you have attended, but Beacon does not hold any sensitive information or financial details such as bank details or credit card information.
Please note that none of our service user data is stored on Beacon. This is held within a different system, so if you have also been involved with GI as a user of our support services this data has not been accessed.
What action is being taken
Beacon is continuing its investigation with external cyber-security specialists and has alerted the relevant authorities. They have implemented immediate security measures to block unauthorised access and are enhancing safeguards to ensure this does not happen again.
As GI we have reported this incident to the Information Commissioner’s Office (ICO) and are following their guidance, and have sent a notification by email to all potentially affected supporters that we have email details for.
We have checked all of other platforms for unusual activity and reinforced our security measures across all of these, but we don’t currently believe that any of these have been affected. We are working with Beacon and their cyber-security experts in the hopes of establishing exactly what has happened and if there are any other actions we might need to take on top of those already taken. We will also be reporting this as a ‘Serious Incident’ to the Charity Commission.
What happens next
We appreciate that this news might be unsettling, and we are sorry that this has happened. There’s nothing you need to fix or change right now, but please remain alert to any unusual interactions claiming to be from us – or other organisations that you support who may have been affected by this incident – over the coming weeks.
We do not communicate with our supporters by SMS, and will rarely communicate with supporters by phone unless initiated by you. If you are ever unsure that a phone call or email from GI is genuine we would much rather you called us back on our publicly available office number or contacted our main email address to confirm.
Please be assured that the security of our supporter data is of extreme importance to us, and we chose Beacon as a suitable platform due to the extensive security measures they already had in place, including being ISO 27001:2022 certified (the most highly-regarded global standard for data security), and Cyber Essentials Plus certified (the highest level of certification in the UK government’s Cyber Essentials scheme).
Once Beacon have concluded their own investigations it will be appropriate for us – as for the many other charities affected – to conduct a comprehensive review of this incident and our ongoing relationship with Beacon, and we will be seeking assurances regarding the safeguards that they propose to prevent a similar issue in future.
We will update this statement if we receive any significantly new information about this incident, but if you have any concerns do reach out to us directly at responses@genderedintelligence.co.uk.