Call us on 01482 622299

Blog

WISHH / News  / Data Breach – 3rd August 2026

Data Breach – 3rd August 2026

We want to let you know about a data security incident affecting a third-party company that we use to manage information relating to fundraisers and donors. The company is called Beacon CRM and they manage the data of over 1,500 charities and organisations nationwide, including the WISHH Charity.

At this time, we are not aware of any misuse of personal information. However, we wanted to inform you of this incident so that you can be vigilant about any possible future misuse.

It is important to note that Beacon CRM is not a financial system and no bank, Direct Debit or card details were stored with your supporter record.

What happened?

On 3 August 2026, Beacon informed us that it had experienced a cyber security incident involving unauthorised access to its systems.

What information may be involved?

The information stored within the Beacon system may include some or all of the following:

Name, email address, phone number, address.

There is no financial information or health information stored within this system.

What action are we taking?

We have reported this incident to the Information Commissioner’s Office and have been working closely with NHS Charities Together who are monitoring the situation.

We are contacting all members and partners affected to make them aware of the incident and will keep in communication with them as the investigation develops.

Beacon has engaged specialist cyber security experts and is continuing to investigate the incident.

We have completed a security checklist provided by Beacon CRM to update all passwords and links.

What should you do?

As a precaution, we recommend that you be vigilant for suspicious emails, telephone calls, text messages or correspondence claiming to be from our organisation or any trusted third party.

Please consider carefully before clicking on links or opening attachments from unexpected communications.

Never disclose passwords, verification codes or financial information in response to unsolicited requests.

What happens next?

We are committed to keeping you informed. If our investigation identifies any further information that may affect you, we will provide an update as soon as possible.

We appreciate that this news will be concerning and we are very sorry for any worry it causes.

Thank you for your support.

Carl Wheatley
WISHH Chief Executive