London Irish Centre FAQs: BeaconCRM Cyber Incident

The incident may have involved some of the personal information we hold about you. We take the security of your information seriously and want to explain what we currently know, what is being done and how you can protect yourself.

What has happened?
Beacon CRM became aware of a cyber security incident on 29 July 2026. They immediately engaged external cyber-security experts to help them investigate and secure their systems. Their understanding was that compromised credentials were used to gain access to Beacon and copies of their database backups were made. Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence so far suggests these copies were likely downloaded. All charities were then contacted on Monday 3 August 2026.

As a result, personal information held by The London Irish Centre within Beacon may have been accessed. Based on the information currently available, we have no evidence that credit-card, bank account information and any other financial details have been mis-used.

Beacon’s investigation is continuing and we will update you of any significant changes

What is being done?
The London Irish Centre is doing the following:

  • Working closely with Beacon to establish exactly what happened and what information may have been affected.
  • Assessing the potential risks to the people whose information we hold.
  • Taking appropriate steps to protect our systems and information.
  • Reporting to incident to the Information Commissioner’s Office (ICO).
  • Beacon has told us that it has taken immediate measures to secure its systems and prevent further unauthorised access. It is also conducting a forensic investigation with external cyber-security specialists.

What you can do
Please remain alert to suspicious emails, telephone calls, text messages or social-media approaches that appear to come from The London Irish Centre or refer to your relationship with us.

In particular:

Be cautious about unexpected requests for money, passwords, banking information or security codes.
Do not open unexpected attachments or follow suspicious links.
Check requests by contacting us through the telephone number or email address on our official website—not by using contact details supplied in a suspicious message.
Please tell us promptly if you receive a suspicious communication that appears to relates to The London Irish Centre.
We are not currently aware of any misuse of the information. These precautions are recommended because criminals sometimes use personal contact information to make fraudulent messages appear convincing.

FAQs

What Happened?

Beacon CRM became aware of a cyber security incident on 29 July 2026. They immediately engaged external cyber-security experts to help them investigate and secure their systems. Their understanding was that compromised credentials were used to gain access to Beacon and copies of their database backups were made. Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence so far suggests these copies were likely downloaded. All charities were then contacted on Monday 3 August 2026.

What Information Has Been Accessed?

This depends on whether you are a Client or Volunteer and how we may have been working with you or supporting you.  The data may include names, contact information and other data.

What should I do right now?

You don’t need to take any action unless we contact you directly.

However, we would advise for you to be cautious of suspicious emails or phone calls and never share personal or banking details unless you’re sure who you’re speaking to.

You can find guidance on staying safe online from the National Cyber Security Centre here.

What has The LIC done to protect your data?

The London Irish Centre takes data security seriously and follows its responsibilities very carefully. The Beacon CRM was chosen partly because of its strong security features, and the charity regularly reviews and updates its security measures ensuring the use of two-factor authentication and regular password updates to keep data secure.  We also regularly review our general policies and procedures relating to data and GDPR.

When notified of the breach on Monday 3 August, The London Irish Centre:

  • Reviewed the information provided by Beacon CRM.
  • Assessed the nature and extent of the potential impact on individuals.
  • Continued to monitor updates from Beacon regarding their investigation.
  • Considered any further actions required under UK data protection legislation.
  • Remained in contact with Beacon regarding the measures they are taking to investigate, contain, and remediate the incident.
  • The incident is being formally reported to the ICO and also the Charity Commission.

The London Irish Centre will continue to carefully monitor the situation, following guidance from Beacon and the ICO, and take further steps if needed.

Why didn’t I receive a letter or email?

On Wednesday 5 August we emailed all contacts for whom we held a valid email address.

If you didn’t get a message, it may be because we didn’t hold an up-to-date email address for you or the email went to your junk or spam folder.

How will I know if a future phone call/email or letter from The London Irish Centre is legitimate?

If you are concerned about any communications at all, please contact [email protected]

 

"(Required)" indicates required fields