The information relates to a cyber-security incident affecting Beacon CRM, the system which the Mental Health Foundation uses to manage our supporter and contact data.
Last updated: 2pm, 5 August 2026.
What has happened?
Beacon CRM recently experienced a cyber-security incident in which an unauthorised third party gained access to their systems. At this stage, Beacon’s understanding is that as a result of the incident an unauthorised third party was able to download data belonging to all organisations that use Beacon CRM. This includes over a thousand charities, including the Mental Health Foundation.
What data does the Mental Health Foundation hold in Beacon?
This will vary depending in an individual’s relationship with the Mental Health Foundation. It may include personal information you’ve shared with us including, but not limited to, name, email address, phone number and address. It may also include a history of how you have interacted with the Mental Health Foundation. We do not hold any information about anybody's medical or mental health history, so no data of this type would have been included in what was accessed as a result of this incident. For people who are donated to us in the past, there is no indication that any credit card or bank details were compromised in this incident.
What is the risk to my data?
There is currently no evidence that this data has been shared on the dark web and there has been no ransom request. This continues to be monitored. The downloaded information could be used to make phishing emails, texts or phone calls. Individuals should be extra vigilant and never share personal details in response to unexpected contact.
What has been done in response to this incident?
On discovering the cyber-security incident, Beacon brought in expert specialists to investigate. They are continuing to work with them to fully understand what has happened and to ensure it cannot happen again. They have set up additional security measures on their systems to help prevent and detect any future unauthorised attempts to access data. Beacon have also issued recommended actions for the users of Beacon CRM to take. The Mental Health Foundation team have completed all of these recommended actions. We have also reported the incident to the Information Commissioner’s Office. We continue to closely monitor this situation and will continue to take any and all necessary steps to ensure the security of the data entrusted to us.
We will keep this page updated with any information related to this incident.