Beacon CRM cyber-security incident: frequently asked questions
Information
Last updated: 7th August 2026
A cybersecurity incident has occurred, affecting Beacon CRM, a third-party provider that provides the system we use to manage information about our members, donors, supporters and service users. This incident may have involved some of the personal data we hold about supporters.
What happened
On Wednesday 29th July 2026, Beacon became aware that it may have experienced a cybersecurity incident. Its current understanding is that compromised credentials were used to gain access to Beacon, and copies of database backups were made.
Beacon notified us of this incident on Monday 3rd August.
What data was involved
Beacon has advised that it is highly unlikely that it will be able to determine exactly what information was affected or which individuals were impacted by this incident.
We are therefore sharing the types of information held within our Beacon account so that you can understand what information may potentially have been involved.
The information we hold in Beacon includes:
Name.
Postal address.
Email address.
Telephone number.
Information relating to eligibility to use Calibre Audio services (for example, that an individual has a visual impairment, but not detailed medical information).
Donation history.
Gift Aid declarations.
Please note that we do not hold payment card details, bank account information or any other financial information within Beacon.
What Calibre Audio and Beacon CRM are doing
Beacon has implemented immediate measures to secure its systems and prevent any further unauthorised access. It is conducting a thorough forensic investigation with the support of external cyber security experts to understand what happened.
At Calibre Audio, we have:
Reported the incident to the Information Commissioner's Office and the Charity Commission.
Assessed the information provided by Beacon and the potential impact on our members, donors, supporters and service users.
Notified members, donors, supporters and service users of the incident and the steps being taken in response.
Continued to work closely with Beacon as its investigation progresses.
How does this affect supporters and what you may do
As always, we strongly recommend that supporters remain vigilant and follow good cyber security practices, including the steps set out below.
Be alert to suspicious emails, phone calls, text messages or correspondence claiming to be from Calibre Audio. If you receive a communication requesting a donation, payment or personal data and are unsure whether it is genuine, please contact us before taking any action.
Do not click on links or open attachments from unknown sources and be cautious of any communication requesting personal data.
If you receive an unexpected call claiming to be from Calibre Audio, end the call and contact us directly. Please note that we will never make unsolicited calls to members, and genuine calls from Calibre Audio will come through our main switchboard rather than a mobile number.
I have recently been contacted about subscriptions, paid £30 or set up a £3 monthly Direct Debit. Is this connected to the Beacon incident?
No. The recent communications about Calibre Audio’s subscription arrangements are separate from the Beacon cyber-security incident.
If you have paid the £30 annual subscription, set up a £3 monthly Direct Debit, or responded to a recent communication from us about subscriptions, your bank account or payment card details are not held in Beacon and were not affected by this incident.
The Beacon incident relates to other personal information held in the system, such as contact and membership information and, where applicable, information about eligibility for our services, donations and Gift Aid.
We appreciate that the timing of the two sets of communications may make them appear connected, but they are separate matters.
For further information or assistance:
Email: dataprotection@calibre.org.uk
Telephone: 01296 432339
Our Membership Services team can help with general enquiries and will refer detailed data-protection questions to Calibre Audio’s Data Protection Officer.
Please contact us if you require this information in an alternative accessible format.