Beacon Cyber Security Incident
August 10, 2026
On Wednesday 29th July 2026, Beacon, our CRM software provider, became aware that they may have experienced a cyber-security incident. They immediately engaged external cyber-security experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of our database backups were made. We were notified by Beacon that they discovered this incident on Monday 3rd August. The incident affects data captured on or before 27 July 2026.
We understand the concern that this will cause to Members, and would like to share the information that Beacon has provided to us, and to let you know what data we hold and what the impact of the breach may have been.
Beacon informs us that there has been no compromise of financial data, as payment information is held by our payment partners – Stripe and GoCardless – and not Beacon. We have taken the step of revoking and resetting the API link between our payment providers and Beacon.
The standard personal data the Ecclesiastical Law Society holds on Beacon is:
- Name
- Address
- Date of birth
- Email address
- In some cases, phone number
- In some cases, profession and/or employer
Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence Beacon has so far suggested these copies were likely downloaded. There is currently no evidence that this data has been shared on the dark web and there has been no ransom request.
Beacon can’t verify, at this time, which of its customer charities have been affected; as such, we are assuming that the ELS is affected.
Beacon has implemented immediate measures to secure its systems and prevent any further unauthorised access. They are now:
- Conducting a thorough forensic investigation with their external cyber-security specialists to understand exactly what happened;
- Working with law enforcement and relevant regulators as required;
- Conducting online monitoring, as is standard practice in these kinds of incidents. So far, they haven’t seen anything of concern;
- Completing precautionary security measures.
We continue to monitor the situation and will be in touch with members again if further concerns or important information comes up.