Skip to main content
News

Beacon CRM security incident

By 11 August 2026No Comments

Bude Sea Pool – Data Security Incident Update

We have been informed that Beacon CRM (customer relationship management), the system used by Bude Sea Pool to manage information about our supporters, donors, volunteers, and other contacts, has experienced a cyber-security incident involving unauthorised access to its systems.

Beacon’s investigation, supported by external cyber-security specialists, has confirmed that copies of encrypted database backups were made and are believed to have been downloaded by an unauthorised third party. Beacon has advised organisations using its system to assume that all data stored in Beacon, including attachment files, may have been downloaded.

Importantly, the information held by Bude Sea Pool in Beacon does not contain bank account numbers, sort codes, card numbers or card security details.

Beacon will continue to provide updates as its investigation progresses. You can read their latest statement here:
Beacon’s latest incident update

We understand that this news may be concerning, and we are very sorry that information people have shared with Bude Sea Pool may have been affected.

We have reported the incident to the Information Commissioner’s Office (ICO) and the Charity Commission, both of whom are aware of and monitoring the situation.

Beacon CRM is used by more than 1,000 charities and organisations and is a trusted provider. It is certified to ISO 27001:2022, the leading international standard for information security, and also holds Cyber Essentials Plus certification.

Although this incident did not originate within Bude Sea Pool, we have taken the opportunity to review our data protection and security arrangements and are continuing to work with Beacon as its investigation progresses.

At present, there is no evidence that any Bude Sea Pool data has been published or misused, and we are not aware of any fraud or harm resulting from this incident.

What should you do?

We recommend being particularly cautious about unexpected phone calls, emails, text messages or other communications that appear to be from Bude Sea Pool or relate to your connection with us. Contact details and other information could potentially be used for phishing or unsolicited communications.

Please:

  • Be cautious about clicking links or opening attachments in unexpected messages.
  • Check the sender’s email address carefully.
  • Never share passwords, bank details or security codes in response to an unsolicited request.
  • If you receive a message that you are unsure about, please contact Bude Sea Pool directly using our usual contact details and we can confirm whether it is genuine.
  • Keep an eye on your accounts for any unusual activity.

We will continue to monitor the situation closely and will share any relevant updates with you as further information becomes available.

If you have any questions or concerns about this incident, please contact Bude Sea Pool at communicationsmanager@budeseapool.org


Latest statement from Beacon