The information relates to a cyber-security incident affecting Beacon CRM, the system which the Mental Health Foundation uses to manage our supporter and contact data.
Last updated: 12.30pm, 6 August 2026.
What has happened?
Beacon CRM, the system that the Mental Health Foundation use for managing our supporter and contact data, experienced a cyber-security incident where an unauthorised third party gained access to their systems. This third party was able to download Beacon’s backup databases containing all client information held in the CRM system. While the data is stored in an encrypted state, it is possible that the unauthorised third party responsible for this incident was able to decrypt it.
What data does the Mental Health Foundation hold in Beacon?
The data we hold varies from individual to individual depending on the information they have shared with us. It may include some or all of:
- Name
- Email address(es)
- Telephone number(s)
- Postal address
- Job title and organisation
- Social media profiles
- Records of donations or payments you’ve made to the Mental Health Foundation
- Information about an individual’s interactions with MHF or that you have provided to us.
For members of our OPEN network, we may hold some additional information where individuals have chosen to share it with us. This includes:
- Ethnicity
- How they assessed their household financial situation, e.g. comfortably off, just managing, finding it difficult.
It does not include:
- Any medical information or anything related to an individual’s mental health
- Credit card information where someone has donated to us
- Bank account information where someone has donated to us
Why might an individual's details be held by the Mental Health Foundation in their CRM?
This will vary from person to person, but we may hold information about individuals in our CRM system for reason, such as:
- Them having signed up for receive our emails.
- Them having made a donation to or organised a fundraiser for the Mental Health Foundation.
- Them having worked with us as a partner, colleague or stakeholder.
- Them having signed up to an event for the Mental Health Foundation.
- Them having joined our OPEN network.
- Them having taken part in a campaign we were running.
In certain circumstances, some records, including those relating to donations and any Gift Aid declarations, must be retained by the Mental Health Foundation for a certain length of time for legal, accounting and HMRC compliance purposes.
What is the risk to my data?
There is currently no evidence that this data has been shared on the dark web and there has been no ransom request. This continues to be monitored. The type of personal data which may have been included in the data breach could be used to make phishing emails, texts or phone calls. Individuals should be extra vigilant and never share personal details in response to unexpected contact.
What has been done in response to this incident?
Since discovering the data-security incident, Beacon have:
- Conducted a thorough forensic investigation with external cyber-security specialists to understand exactly what’s happened;
- Worked with law enforcement and relevant regulators as required;
- Conducted continuing online monitoring of the dark web, as is standard practice in these kinds of incidents. So far, they haven’t seen any reference or data linked to this incident;
- Issued guidance to all customers of Beacon CRM on steps to ensure their systems are secure;
- Deployed additional security measures across their systems to help detect and prevent further unauthorised access.
Since being informed of the data-security incident, Mental Health Foundation have:
- Carried out all relevant actions as recommended by Beacon;
- Notified the Information Commissioner’s Office (ICO);
- Discussed the situation with the Charity Commission;
- Begun communicating about the incident to everyone affected, where we have up-to-date contact information.
We will keep this page updated with any information related to this incident.