News > Beacon Data Security Incident Statement
August 10, 2026
Beacon Data Security Incident Statement
Balloons is one of many charities and non profit organisations across the UK to have been affected by a recent cyber security incident involving Beacon CRM, the third-party database provider used by Balloons, to manage supporter and donor contact information.
We take the privacy and security of personal information extremely seriously. Whilst there is currently no evidence that personal information has been misused, we believe it is important to be transparent about what has happened, the information that may have been affected, and the steps we have taken in response.
What Happened?
On 29 July 2026, Beacon CRM identified unauthorised access to its systems and immediately engaged external cyber security specialists to investigate and contain the incident.
Beacon CRM has advised us that the current evidence indicates that copies of affected database backup files were likely to have been accessed and downloaded by an unauthorised third party.
The investigation remains ongoing and Beacon CRM continues to work with specialist investigators to establish the full circumstances of the incident.
Balloons was notified of the incident on 3 August 2026. This incident has affected a number of charities and non-profit organisations that use the Beacon CRM platform.
What Information May Have Been Involved?
Based on the information provided to us by Beacon CRM, the affected database backups may have contained supporter and donor contact information held by Balloons, which could include:
- Name
- Email address
- Telephone number
- Postal address
The affected records may also indicate whether people have previously engaged with or supported Balloons.
Importantly, Beacon CRM does not store any payment card details, bank account information, sort codes or online account passwords.
No information relating to the support work we do with children, young people or families is held in the Beacon database and are therefore is not affected by this incident.
What Is Our Current Assessment?
Based on the information currently available:
- We have seen no evidence that Balloons supporter or donor information has been publicly disclosed.
- We have seen no evidence of identity theft, fraud or other misuse of personal information arising from this incident.
- We have received no reports suggesting that any affected information has been published online.
The principal foreseeable risk is that personal contact information could potentially be used in phishing attempts, scam communications or other unsolicited contact.
We will continue to monitor the situation closely and review our assessment as further information becomes available from Beacon CRM’s ongoing investigation.
What We Have Done
As soon as we became aware of the situation, we took immediate action:
- Completed all remediation and security measures recommended by Beacon CRM.
- Reviewed the categories of Balloons data potentially affected.
- Conducted an assessment of the potential risks to our supporters and donors.
- Established ongoing communication with Beacon CRM regarding the investigation and any developments.
- Put in place continued monitoring and review arrangements.
- Contacted supporters and donors to inform them of this incident.
We have also informed the Information Commissioner’s Office (ICO) that Balloons data forms part of this wider incident and will continue to review whether any further notifications or actions are required as additional information becomes available.
What should anyone affected do?
Although there is currently no evidence that personal information has been misused, we recommend all supporters take the following precautions:
- Be Vigilant Against Phishing
- Be cautious of unexpected emails, text messages or telephone calls claiming to be from Balloons, Beacon CRM or any other organisation asking you to provide personal or financial information.
- Verify Requests for Information
- Balloons will never make contact unexpectedly to ask for bank account details, payment card information or passwords. If you receive such a request, you should not provide any information and should contact us directly.
- Take Care with Links and Attachments
- Avoid clicking links or downloading attachments from unexpected or suspicious messages. If you are unsure whether a communication is genuine, please contact us before responding.
We Are Here to Support You
We sincerely regret that this incident has occurred and understand that news of a data security incident may cause concern. Protecting the information entrusted to us is extremely important.
We will continue to monitor the situation closely and will provide further updates if significant new information emerges from the ongoing investigation.
If you have any questions or concerns, please contact Balloons using the details below.
Nicola Clarke
CEO – Balloons
01392 982570
