Dear Supporter,
I am writing to let you know about a security incident affecting Beacon CRM (Client Relationship
Management) system. This is a system used by The Wye and Usk Foundation and hundreds of other
charities to manage information about our donors, partners and contacts.
What happened?
On 3 August 2026, Beacon informed us that an unauthorised party had gained access to its systems
using compromised credentials. Copies of Beacon’s database backups were made and Beacon
believes they were likely downloaded, although its investigation is continuing.
Though encrypted, the potential information accessed includes: names, contact details, donation
dates and amounts and some recent correspondence on personal records.
Donor banking details and payment card information are not stored within our Beacon CRM system and
have not been compromised.
What are the possible risks?
There is currently no evidence that your information has been published or misused, and we are not
aware of any fraud or harm resulting from this incident. However, the information could potentially
be used to make phishing emails, telephone calls or fraudulent requests appear more convincing.
As you will be well aware, the risk of cyber security threats are ever increasing. We recommend that
all our supporters remain vigilant for any unexpected phone calls, messages, and emails, consider
using strong passwords and take extra care clicking links or opening attachments in any emails that
are unusual.
For additional security tips, please consult this information page from the National Cyber Security
Centre: https://www.ncsc.gov.uk/guidance/data-breaches
What action has been taken?
Beacon is continuing its investigation with external cyber-security specialists and has alerted the
relevant authorities. The Wye and Usk Foundation has completed all the recommended security actions
as advised by Beacon. The Foundation has also formally reported the incident to the Information
Commissioner’s Office (ICO). They have confirmed that they do not plan to make any further
contact with us.
Next steps
Beacon and The Wye and Usk Foundation are taking this incident extremely seriously. Beacon have
implemented immediate security measures to block unauthorised access and are enhancing safeguards to
ensure this does not happen again.
The Wye & Usk Foundation will continue to monitor Beacon's investigation and implement any
further recommendations that arise.
We understand that this news may be concerning and we apologise for any worry and stress this
incident may cause. If you have any questions or wish to raise any concerns with us you can email us
at dataprotection@wyeuskfoundation.org