**Published: 5 August 2026**
At TheGivingMachine, protecting the personal information you trust us with is one of our highest priorities. We are informing you of a data security incident affecting one of our suppliers, and to explain the steps we are taking in response.
What happened
On Monday 3 August 2026, we were notified of a cyber security incident affecting Beacon, the CRM software provider that holds our contact data.
Beacon is currently investigating the incident with the support of external cyber security specialists, and the full circumstances are not yet known. Beacon's current understanding is that an unauthorised third party used compromised credentials to gain access to its systems, and copied data held there. Beacon is unable to confirm whether our data was included.
Beacon stores data in an encrypted format; however, it is possible the unauthorised third party was able to decrypt it.
What Beacon is doing
Having identified the probable root cause of the unauthorised access, Beacon has:
- Remediated the vulnerability that allowed access
- Reset credentials for all services and accounts integrated with Amazon Web Services (AWS)
- Deployed security software to continuously monitor its systems for Indicators of Compromise and suspicious activity, with automatic removal of any threats identified
Beacon is one of the largest CRM providers for charities in the UK. This incident has affected a large number of charities across the country, and TheGivingMachine was not specifically targeted.
What we are doing
As soon as we were notified, we took immediate action:
- We reported the incident to the relevant regulatory and governing bodies, including the Information Commissioner's Office (ICO), the Charity Commission, and the Gambling Commission.
- We contacted everyone whose data we hold to inform them of the incident.
- We are working closely with Beacon as their investigation continues, and will update this page as we learn more.
Next steps for you
There is no immediate action required on your part. As a precaution, we recommend:
- Staying alert to unexpected or suspicious emails, calls, or messages - particularly anything claiming to be from TheGivingMachine
- Avoiding clicking links or sharing personal information in response to unsolicited communications
- Verifying the sender before responding to any message that asks for personal or financial details
Our commitment to you
TheGivingMachine takes the security of personal data extremely seriously. We are working with all relevant authorities to manage this situation and remain fully committed to keeping you informed as it develops. The security of your data is, and will remain, our priority.
Questions or concerns
If you have any questions or concerns about this incident, please contact us at info@thegivingmachine.co.uk.