Beacon incident
On 3 August 2026 we were notified about a cyber security incident involving the Beacon database. Beacon is the system we, and 1,500 other charities, use to manage information about the people who contact and support our charity.
We have been told by Beacon that an unauthorised third party gained access to their systems. Beacon told us that it contained the incident and has now concluded its investigation into the extent of the breach.
Beacon’s assessment is that the unauthorised third party likely exported all data contained within its database. Beacon has explained that the third party used valid credentials to access its information. As a result, Beacon says that any data downloaded would have been decrypted and made available to the third party in a legible form.
Beacon cannot identify the specific files or records that were downloaded. It has therefore not confirmed which particular records relating to Care Rights UK or the people who contact/support us were included. However, in light of Beacon’s assessment, we are proceeding on the basis that all information held in our Beacon account may have been downloaded.
We understand that no financial information relating to the people we support or who support the charity was affected by this incident.
Beacon told us that the unauthorised third party contacted them to indicate they would be deleting any data they have exfiltrated and no copy would be retained, sold or shared. Beacon did not respond to this contact.
We are sorry that this has happened. We appreciate that news like this may be concerning to the people who contact and support our charity. Protecting your personal information is extremely important to us, and we take these matters very seriously.
Do I need to take action?
Beacon has said that it has not found any evidence that information affected by the incident has been published, disclosed or otherwise misused. It is continuing to monitor for any indication of this.
As a precaution, we recommend that you:
Remain vigilant to any unexpected emails, calls, texts or letters, particularly where someone claims to be from Care Rights UK, Beacon or another organisation you know.
Do not transfer money or provide authentication codes or any personal or financial information in response to an unexpected communication. Do not divulge your passwords.
Verify unexpected requests or anything that seems unusual before responding, opening attachments, or clicking links – verify using contact details obtained independently, rather than a telephone number, email address or link supplied in the communication.
Remain vigilant about your bank and payment account statements and report any unfamiliar activity promptly to your bank or payment provider.
Contact us if you receive a suspicious communication which appears to relate to us or to information you have shared with us.
If another person normally supports you with correspondence or financial matters, you may wish to make them aware of this message so that they can help you identify anything unusual.
What are Care Rights UK doing?
As soon as we were notified about this incident, we responded to do what we can to secure our own systems. We are working closely with Beacon, alongside other charities affected by this incident, to understand how it occurred. We selected Beacon as our database provider because it met the high security standards and certifications we expect from a supplier entrusted with your information. We have also notified the regulator, the Information Commissioner’s Office (ICO). The ICO has confirmed that it has closed the case and does not require any further action from us at this stage.
Further information
Beacon’s report of their investigation is available on their website.
We will provide any further updates on developments on this page. If you have any immediate concerns, please contact us on team@carerightsuk.org
Please see Action Fraud’s resources for advice on how to remain vigilant about your cyber security: www.actionfraud.police.uk/individual-protection
Page last updated: 8 September 2026 to reflect the further information provided by Beacon, following the conclusion of its investigation.