YMCA Cornwall
Lisa Woodruff
|
17 August 2026

Important Notice: Beacon CRM Security Incident

Important Notice: Beacon CRM Security Incident

Beacon CRM Security Incident

YMCA Cornwall has been informed by Beacon CRM (our customer relationship management provider) that it has experienced a cyber-security incident involving unauthorised access to its systems.

Beacon has informed YMCA Cornwall that copies of database backups have been accessed and downloaded by an unauthorised third party. As a result, information that YMCA Cornwall stores within Beacon CRM may have been affected.

What information may be affected?

The personal information we hold within Beacon CRM may include:

  • Name
  • Postal address
  • Email address
  • Telephone number
  • Donation history (and the campaigns the donations were linked to)
  • Communication preferences
  • Gift Aid information (where applicable)

At this stage, there is no evidence that any personal data has been published or misused. However, we are contacting you as a precaution because your information may have been affected.

What information is NOT affected?

YMCA Cornwall does not store bank card details (used to make donations), or individuals dates of birth on Beacon CRM, meaning this information has not been compromised as a result of this incident.

What action has YMCA Cornwall taken?

As soon as we were informed of the incident, we:

  • Contacted Beacon CRM to obtain further information regarding the breach.
  • Reported the incident to the Information Commissioner’s Office (ICO).
  • Temporarily stopped using Beacon while cyber-security specialists assessed the severity of the attack and then confirmed it was safe to resume using the service.
  • Followed Beacon’s recommended course of action by notifying individuals whose data may have been involved.

Beacon has engaged specialist cyber security experts to investigate the incident and has implemented measures to secure its systems and prevent further unauthorised access.

What should you do?

While there is currently no evidence that personal information has been misused, we encourage everyone to remain vigilant.

Please be cautious of:

  • Unexpected emails, text messages or phone calls requesting personal       information.
  • Messages asking you to click on links or download attachments.
  • Requests for passwords, banking information or payment details.

YMCA Cornwall will never contact you unexpectedly asking for passwords, PINs or sensitive financial information.

Our apology

We understand that this news may be concerning and we sincerely apologise for any worry or inconvenience this incident may cause.

Protecting the personal information entrusted to us is extremely important. We take our responsibilities regarding data protection seriously and are working closely with Beacon CRM to understand the full impact of this incident and ensure appropriate safeguards remain in place.

Further information

We will provide updates on our website when further information becomes available.

If you have any questions or concerns, please contact: penzanceadmin@ymcacornwall.org

Thank you for your understanding and continued support of YMCA Cornwall.

Share article

Link copied to clipboard
Back to news