Quick Exit
News
|
Posted 11th August

Beacon CRM Cyber Security Incident

Beacon CRM Cyber Security Incident

You may have recently heard reports in the media about a cyber security incident affecting Beacon CRM, a customer relationship management (CRM) system used by a number of charities and organisations across the UK, including The Green House.

Protecting the confidentiality of the people who use our services is one of our highest priorities. We understand that news of this incident may be concerning and we want to reassure those who may be affected that we are taking the matter extremely seriously.

What happened?

On 3rd August 2026, Beacon CRM informed us that it experienced a cyber security incident affecting its systems. Beacon is a specialist third-party supplier that securely stores information on behalf of organisations, such as The Green House.

As soon as we were notified, we began working closely with Beacon to understand what had happened, what information may have been affected and whether there was any impact on the people who use our services.

Why was The Green House using Beacon?

Like many charities, we use specialist third-party providers to help us deliver our services safely and effectively.

Before appointing any organisation to process personal information on our behalf, we undertake appropriate due diligence. This includes assessing their security arrangements, compliance with UK data protection legislation and, where appropriate, recognised information security standards such as ISO/IEC 27001. Unfortunately, even organisations with robust security controls can become the target of increasingly sophisticated cyber-attacks.

What information may have been affected?

Although Beacon has not confirmed that The Green House’s data was directly affected by this incident, the trust our clients place in us is paramount. We believe it is important to be open and transparent about the possibility that information we hold on your behalf may have been affected, even where investigations are ongoing and the full picture is not yet known. Data we hold includes:

  • Names
  • Addresses
  • Emails
  • Phone Numbers
  • Lived Experience

We want to reassure our community that at present we have no evidence that this information has been misused; but wanted to let you know for transparency as the information stored in the wrong hands could be used to commit fraud.

What is The Green House doing?

Since becoming aware of the incident we have:

  • Worked closely with Beacon to understand the nature and scope of the incident and followed their immediate security recommendations
  •  Undertaken our own risk assessment
  •  Reported the incident to the Information Commissioner’s Office (ICO)
  •  Reviewed the information held within Beacon and any potential impact on individuals
  •  Reviewed the scope of data we hold on individuals and deleted data accordingly
  •  Reviewed our own data holding policies
  •  Continued to monitor the situation and seek updates from Beacon
What should I do?

You do not need to take any immediate action but we recommend that you:

  • Be cautious of unexpected emails, telephone calls, text messages or social media enquiries
  • Do not provide passwords, payment information or other personal details in response to an unexpected message
  • Do not click on links or open attachments unless you are confident that the message is genuine
  • Contact us directly if you receive anything suspicious claiming to be from The Green House.

Useful information on protecting yourself from cybercrime can also be found here.

You also have the right to contact the Information Commissioner’s Office if you have concerns about how your personal information has been handled. Further information is available at www.ico.org.uk

We sincerely regret any concern this incident may cause. We recognise the trust that people place in us when they share their personal information and we remain committed to protecting that information and being transparent about incidents such as this.

If you have any questions or concerns, please contact our data protection officer using the e-mail address below:

Josh Taylor
josh.taylor@the-green-house-org.uk

Other Articles

For Survivors
Posted 16th July
When My Mind Turned Against Me
Read More
Blog Article
Posted 9th June
Shaping the future of Victims’ Rights
Read More
Blog
Posted 19th May
Winning The 2026 GSK IMPACT Award: A Reflection
Read More