Third Party Data Security Incident

We would like to let you know about a data security incident affecting Beacon, the third party Customer Relationship Management database (CRM) that we use to manage data relating to our donors and supporters, both past and present.

At this time, we are not aware of any misuse of personal information. However, as an organisation committed to transparency and honesty, I felt it important to inform you of this incident.

It is important to note that Beacon CRM does not store any bank or card details from our donors. These remain secure with third party payment processors with firm security in place.

What happened?

On 3 August 2026, Beacon CRM informed us that it had experienced a cyber security incident involving unauthorised access to its systems. Beacon CRM has engaged specialist cyber security experts and is continuing to investigate the incident. This incident is not specific to Full Fact and likely affects all of the 1,000+ charities that use Beacon CRM.

What information may be involved?

Beacon CRM’s investigation is ongoing. The information we store within our Beacon CRM system may include some or all of the following for donors. If you have never donated to Full Fact, and you don't work for one of our partner organisations, your data is not affected.

  • Name
  • Postal address
  • Email address
  • Telephone Number
  • Donation information and activity
  • Gift Aid status

What are we doing?

Protecting the personal information of our donors and supporters is extremely important to us.

Since being notified of the incident, we have:

  • Reviewed the information that may have been affected
  • Completed Beacon CRM’s security checklist
  • Assessed the potential risks to the individuals whose information we hold
  • Considered our legal obligations under data protection law
  • Reported the breach to the Information Commissioner's Office (ICO)
  • Continued to monitor developments as Beacon's investigation progresses

What should you do?

We are not currently aware of any misuse of your personal information as a result of this incident. However, as a precaution, we recommend that you:

  • Remain vigilant for suspicious emails or correspondence claiming to be from our organisation or any trusted third party
  • Exercise caution before clicking on links or opening attachments from unexpected communications
  • Never disclose passwords, verification codes or financial information in response to unsolicited requests

Where can I get more information?

We appreciate that this news may be concerning and we’re very sorry for any worry it causes.

We are committed to keeping you informed. If our investigation identifies any further information that may affect you, we will provide an update as soon as possible to anyone impacted. You can read more about the data breach on Beacon CRM’s website.

If you have any questions please use our contact form to get in touch.

Thank you for your support.

Anna Jones

Head of Income and Operations

5th August 2026