Beacon CRM cyber-security incident: frequently asked questions

FAQs

Last updated: 5th August 2026

Calibre Audio is contacting people whose personal information was held in Beacon CRM and may have been affected by a cyber-security incident involving Beacon.

This page provides further information about what happened, what information may have been involved, what Calibre Audio has done and the steps you can take.

What happened?

Beacon CRM, a third-party system used by Calibre Audio to manage member, supporter and fundraising information, experienced unauthorised access to its systems.

Beacon’s investigation found that copies of customer database backups were made and were likely downloaded by an unauthorised third party. Beacon has identified activity consistent with information leaving its systems.

Was the information definitely downloaded?

Beacon has said that the database backups were likely downloaded. It cannot determine precisely which individual records were involved.

Beacon has advised its customers to assume that all information stored in their Beacon accounts, including attached files, may have been downloaded. Calibre Audio is therefore treating the relevant information held in its Beacon account as potentially affected.

Was the information encrypted?

Beacon stores information in an encrypted state. However, Beacon’s cyber-security specialists have advised that it is possible the unauthorised third party was able to decrypt the information before copying it.

We are therefore proceeding on the basis that the information may have been readable.

Why have I been contacted?

You have been contacted because Calibre Audio’s review identified that information about you was held in Beacon CRM and may have been included in the affected data.

You may be a current or former member, donor, supporter or someone who has previously had another relationship with Calibre Audio.

Receiving a notification does not mean that all the categories of information listed below were held about you.

What information may have been affected?

Depending on your current or previous relationship with Calibre Audio, the information may have included:

  • your name and contact details;

  • your date of birth;

  • current or previous membership information;

  • information about your eligibility for Calibre Audio’s services, which in some cases may include disability-related information;

  • communication preferences;

  • donation or fundraising information;

  • Gift Aid information; and

  • information contained in documents or files attached to a Beacon record.

Not every category applies to every person.

Were audiobook borrowing and listening records affected?

No. Calibre Audio’s audiobook borrowing and listening records were not stored in Beacon CRM and are not part of the information affected by this incident.

Were payment-card details affected?

Beacon does not store full payment-card details on its servers and has said that there is no evidence that card details were compromised.

Calibre Audio is not advising people to cancel or replace payment cards as a result of the information currently available.

Has the information been published or misused?

There is currently no evidence that personal information held by Calibre Audio has been published or misused.

Beacon has also said that its monitoring has not identified any information linked to the incident on the dark web. However, the investigation and monitoring are continuing.

What are the possible risks?

The information could potentially be used to make fraudulent emails, telephone calls or messages appear more convincing.

The possible consequences include:

  • phishing or fraudulent communications;

  • attempts to obtain passwords, banking information or security codes;

  • distress or concern;

  • loss of confidentiality; and

  • increased risk of scams tailored using personal information.

There is currently no evidence that any of these consequences have occurred in relation to Calibre Audio’s information.

What should I do?

Please remain alert to unexpected communications.

  • Check the sender before responding to an email, call or message.

  • Avoid clicking unexpected links or opening unfamiliar attachments.

  • Never disclose passwords, banking information or security codes in response to an unsolicited request.

  • Be cautious where someone creates urgency or pressures you to act immediately.

  • Contact Calibre Audio using our established contact details if you are unsure whether a communication claiming to be from us is genuine.

The ICO recommends giving affected people clear advice that helps them protect themselves from phishing and fraudulent activity.

Do I need to contact Calibre Audio?

You do not need to contact us simply to confirm that you have received the notification.

Please contact us if:

  • you receive a suspicious communication that appears to use information connected with Calibre Audio;

  • you believe information about you has been misused;

  • you have concerns about the categories of information that may have been involved;

  • you need the information in an alternative accessible format; or

  • you have another question that is not answered on this page.

What has Calibre Audio done?

Calibre Audio has:

  • secured its connections with Beacon;

  • replaced relevant access credentials;

  • reviewed and secured relevant third-party integrations;

  • assessed the information held in Beacon;

  • identified the people who should receive direct notification;

  • reported the breach to the Information Commissioner’s Office;

  • submitted a Serious Incident Report to the Charity Commission;

  • briefed relevant staff on handling enquiries; and

  • continued to document and review the incident and the measures required to reduce the risk of recurrence.

The ICO requires organisations to document personal data breaches, their effects and the remedial action taken.

Has Beacon secured its systems?

Beacon has said that it identified the probable cause of the unauthorised access, remediated the vulnerability and reset relevant credentials.

Beacon has introduced additional security monitoring and says its external cyber-security specialists have not identified any continuing unauthorised access since the incident was contained.

Is Beacon still operating?

Yes. Beacon has said that its service remains operational and that it did not experience a service interruption as a result of the incident.

Have the relevant authorities been informed?

Yes. Calibre Audio has reported the personal data breach to the Information Commissioner’s Office.

As a registered charity, Calibre Audio has also submitted a Serious Incident Report to the Charity Commission.

Beacon has separately reported the incident to the Information Commissioner’s Office and Report Fraud.

Why did Calibre Audio still hold information about me?

Calibre Audio retains personal information for as long as it is required to provide services, administer relationships, comply with legal obligations and maintain appropriate organisational records.

Under Calibre Audio’s retention schedule:

  • member records are normally retained for up to two years after membership becomes inactive;

  • donor and supporter records are normally retained for six years after the last donation; and

  • Gift Aid records are retained for six years following the end of the relevant accounting period.

Some information may need to be retained for longer where there is a legal, regulatory, safeguarding or evidential reason.

Can I ask Calibre Audio to delete my information?

You have data-protection rights, which may include the right to request access, correction or deletion of your personal information.

These rights are subject to legal exceptions. Calibre Audio may need to retain limited information where required by law or for regulatory, safeguarding or evidential purposes.

Requests should be sent to our Data Protection Officer using the contact details below.

Will you provide further updates?

Yes. Calibre Audio is continuing to review the incident and the information that may be affected.

We will update this page and contact affected individuals again if material new information becomes available that changes the risks or the advice being provided.

How can I contact Calibre Audio?

For further information or assistance:

Email: dataprotection@calibre.org.uk
Telephone: 01296 432339

Our Membership Services team can help with general enquiries and will refer detailed data-protection questions to Calibre’s Data Protection Officer.

Please contact us if you require this information in an alternative accessible format.