News
Print Article

Eight Jersey charities hit by Beacon CRM data scare

09/08/2026

At least eight Jersey charities have reported a potential data incident linked to UK CRM provider Beacon, after unauthorised access to database backups.

Jersey’s Information Commissioner, Paul Vane, confirmed that eight local organisations had contacted his office by early afternoon on 6 August 2026. The charities were notified by Beacon CRM, a UK-based software firm used by more than 1,500 charities and voluntary organisations, of a cyber-security incident involving possible unauthorised access to customer databases.

Beacon CRM (operated by Beacon Apps Ltd) is a UK-based software company that provides a specialised Customer Relationship Management (CRM) platform built exclusively for charities and voluntary organisations.

Macmillan Cancer Support Jersey was the first Island charity to go public, stating on 4 August that it “could have been affected” because Beacon held its supporter data.

Others that have issued similar statements include:

  • Jersey Trees for Life,
  • Healing Waves and
  • The JSPCA Animals’ Shelter.

Mr Vane said his office is aware of the situation and is liaising with UK counterparts. Because Beacon is a UK provider, primary regulatory responsibility sits with the UK Information Commissioner’s Office (ICO). He noted: “Beacon CRM is a UK-based provider and therefore would fall under the UK information commissioner’s regulatory remit.”

What is known about the incident

Beacon became aware of the issue on or around 29 July 2026. Its investigation, supported by external cyber-security specialists, indicates that compromised credentials (described in some updates as a more sophisticated access key rather than a simple username/password) were used to gain access.

Copies of database backups were made, and the evidence points to these having been downloaded. Beacon has stated there is currently no evidence the data has appeared on the dark web and no ransom demand has been received. Systems were contained and remain operational.

Beacon has reported the matter to the ICO (case number IC/0238/2026) and to authorities via Report Fraud. It advises customers to assume, as a precaution, that data held in Beacon accounts (including attachments) before the containment window may have been affected.

Data involved and reassurances from Jersey charities

Affected organisations have stressed that bank account and payment card details are not stored in Beacon systems; separate payment processors handle these. Typical data potentially exposed includes names, postal and email addresses, telephone numbers, donation histories, Gift Aid status, and in some cases limited additional supporter or volunteer information.

Local statements have emphasised transparency and the absence of evidence of misuse so far. The JSPCA said it was “genuinely sorry this has happened” and takes the protection of personal information “extremely seriously”. Jersey Trees for Life adopted a precautionary approach while confirming it was too early to say whether its data had been compromised. Healing Waves co-founders Max Wiltshire and Dominic Booth noted the incident involved a trusted supplier rather than their own systems and highlighted their commitment to openness with supporters.

Wider impact and regulatory response

The same incident has prompted notifications from numerous UK organisations, including Breast Cancer UK, the Institute for Voluntary Action Research, English National Ballet, Full Fact, Molly Rose Foundation, Sheffield Hospitals Charity, LawCare and others.

The UK Charity Commission issued guidance on 7 August 2026, confirming it is monitoring the situation, is in contact with the ICO, and encouraging trustees to follow serious incident reporting rules where appropriate and to review cyber-crime guidance.

A spokesperson for Jersey’s Charity Commissioner confirmed awareness of the incident and advised any organisation with concerns to contact that office or the Jersey Office of the Information Commissioner (jerseyoic.org).

Charities involved have urged anyone with concerns to contact them directly. Supporters have generally been advised to remain alert to unexpected communications that could indicate phishing attempts, while noting that no evidence of actual misuse or fraud linked to this incident has been reported at the time of writing.

Ongoing and developing

This is a developing situation. The precise scale of data downloaded and any subsequent misuse remain under investigation. Always cross-check the latest updates directly from Beacon, the ICO, the Jersey Office of the Information Commissioner, and the individual charities concerned.

Key sources for verification

CHARITY UNITED KINGDOM JERSEY CYBER DATA PROTECTION DIGITAL TRUST

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

Contact

Think we can help you and your business? Chat to us today

Get In Touch

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.