Data Breach at Beacon CRM Affects Cultural Organizations

Data Breach at Beacon CRM Affects Cultural Organizations

First seen 4 Aug 2026, 15:21 UTC www.gov.ukScvo.ScotArtsprofessionalCivilsocietyico.org.uk+46 85% similarity 57.6

Article Content

Browse articles
ThreatCluster

Beacon CRM, a customer relationship management platform used by many cultural organizations, reported a cyber-security incident involving unauthorized access to its database backups. The breach, identified on July 29, 2026, involved compromised credentials that may have allowed attackers to download copies of sensitive data. Affected organizations include the English National Ballet and Chiswick House and Gardens Trust, which are notifying their stakeholders about the potential exposure of personal information. While there is no evidence of data being published or misused, the incident raises concerns about phishing attacks using the compromised data. Beacon is conducting a forensic investigation and has advised its clients to assess their data protection obligations. The Information Commissioner’s Office (ICO) has been informed, and organizations are urged to report the breach if it poses a risk to individuals' rights and freedoms.

Key Points: • Beacon CRM experienced a cyber incident with unauthorized access to database backups. • Compromised credentials were used, and sensitive data may have been downloaded. • Affected organizations are advised to notify stakeholders and assess their reporting obligations.

ThreatCluster AI How this analysis works

Timeline

2026-07-29
Beacon CRM identifies cyber-security incident
Beacon CRM became aware of unauthorized access to its systems, prompting an investigation with external experts.
www.beaconcrm.org
2026-08-03
Beacon informs customers about data breach
Beacon updated its customers regarding the cyber incident and the potential risk to their data.
Scvo.Scot
2026-08-04
Beacon CRM issues public statement
Beacon confirmed that copies of database backups were likely downloaded and provided guidance for affected organizations.
Artsprofessional
2026-08-04
ICO notified of the incident
The Information Commissioner’s Office has been informed and is assessing the situation based on reports from affected organizations.
Civilsociety

Community

Browse all →