What Happened?
Alongside approximately 1,000 other charities, we use a well-established UK-based Customer Relationship Management (CRM) platform called Beacon. We use Beacon to store data relating to active contacts, members, staff and volunteers, and, in line with data retention requirements, data on some historic contacts.
On 27 July 2026, an unauthorised third party gained access to Beacon’s system using a stolen access key. From Beacon’s investigation, there is evidence they then made and downloaded a copy of Beacon’s entire customer database.
As a customer of Beacon, this means that the London Irish Centre’s data was also compromised. However, Beacon cannot confirm whether specific objects were downloaded or what their destination was.
After the initial incident, there has been no further suspicious activity or ongoing unauthorised access to Beacon’s systems. During their investigation, Beacon’s team received contact from the threat actor, indicating they would be deleting this data and that no copy would be retained, sold, or shared.
Beacon has been monitoring the dark web extensively for any reference to this data, and so far, have found no evidence that any compromised data has been sold or shared. There’s also no indication this was a targeted attack on Beacon CRM or any specific customer.
Beacon has issued a final report on the incident, which can be accessed here.
Has my data been exposed?
Beacon has evidence that all data on their systems was copied and downloaded by this threat actor. As a customer of Beacon, this means that the London Irish Centre’s data was also compromised. However, Beacon cannot confirm whether specific objects were downloaded or what their destination was.
How has The London Irish Centre responded?
The London Irish Centre takes data security seriously and follows its responsibilities very carefully. The Beacon CRM was chosen partly because of its strong security features, and the charity regularly reviews and updates its security measures, ensuring the use of two-factor authentication and regular password updates to keep data secure. We also regularly review our general policies and procedures relating to data and GDPR.
When notified of the breach on Monday 3 August, The London Irish Centre:
As a customer of Beacon, we notified the Information Commissioner’s Office (ICO) of the incident when it occurred. Our own case with the ICO has now been closed, as the breach occurred on Beacon’s platform rather than within the London Irish Centre’s own systems.
What should I do?
There has been no evidence that any of your data has been sold or shared, and you do not need to take any action.
However, it is important to remember that those who carried out this breach are criminal actors, and their assurance that the data will be deleted comes with no guarantee.
We urge you to remain vigilant about unexpected emails, text messages, phone calls or requests for personal information. The London Irish Centre will never unexpectedly ask you to provide passwords, payment details or other sensitive data.
Please remember:
We understand that this situation may be concerning. Although Beacon have published a final incident report and appears to be treating the case as closed, we are continuing to monitor the situation and will keep you informed if we receive any further information that is relevant to you.
There is no need to contact us unless you have a specific concern or question. If you do need to get in touch, please contact [email protected].
You can find guidance on staying safe online from the National Cyber Security Centre here.
What data are you holding for me?
The information we hold about you depends on how you have interacted with the London Irish Centre and the services you have accessed or provided.
We use Beacon, our Customer Relationship Management (CRM) system, as a case management tool. It helps us keep an accurate record of our interactions with you, provide and coordinate services, communicate with you where appropriate, and hold data which allows us to provide accurate reports to our funders.
The information we hold will have been provided to us by you, either directly or as part of your interaction with the London Irish Centre. Different people will have different information held about them, depending on their circumstances. We do not hold all of the types of information listed below for every person.
Depending on your relationship with the London Irish Centre, we may hold information such as:
We only hold information that is relevant to our relationship with you and the services or opportunities you have accessed. The specific information we hold will depend on your individual circumstances.
If you would like to know exactly what personal information we currently hold about you, please contact our Data lead at [email protected]. We will provide you with further information about the personal data held on our records as soon as practicable.
Why do you have my data?
The data that we hold for you has come directly from you, whether through direct contact or your use of our services. In line with GDPR regulations, we have managed this data to ensure that we can:
We only hold information that is relevant to our relationship with you and the services or opportunities you have accessed.
Why have you shared my data?
The London Irish Centre uses Beacon, a specialist Customer Relationship Management (CRM) system, to help us manage and deliver our services. Beacon is an established, award-winning software provider used by more than 1,000 charities across the UK and internationally.
We use Beacon as a case management tool to help our teams securely record and manage information that is relevant to the services we provide. For example, it allows us to keep appropriate records of the support you have received, understand your needs, manage your interactions with us and help us provide an effective and consistent service.
We only record information that is relevant and necessary for the services or support we provide to you. The information held will vary depending on your individual circumstances and your relationship with the London Irish Centre.
Beacon is our software provider; it is not providing services to you on our behalf. Beacon provides the technology that allows us to manage our information and case records. Beacon’s staff do not use your information to provide services to you and do not have access to your records as part of the normal operation of our services.
Using specialist software providers such as Beacon is a standard way for organisations like the London Irish Centre to securely manage case information and deliver effective services. We remain responsible for how your information is used and are continuing to work with Beacon as their investigation into this incident progresses.
Is my information safe with the London Irish Centre?
Yes. This incident did not occur because the London Irish Centre misplaced your information, or because our own systems were directly breached.
The security incident occurred within Beacon’s systems and has affected information held by more than 1,000 organisations that use Beacon’s software.
Beacon has fixed the vulnerability that allowed access, reset all credentials that could have been affected, and engaged independent cyber-security specialists to confirm no further unauthorised access had occurred. A second, independent security firm has since reviewed Beacon’s response and confirmed it was effective, with the incident properly closed out and Beacon’s systems left more secure than before.
Be the first to hear about events, rafflles, competitions, fundraisers, impact stories & more.
"(Required)" indicates required fields