We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept", you consent to our use of cookies. Cookie Policy

Donate Become a Mentor

Become a Mentor

Become a Mentor

For donations

Donate

Other ways to support

Important Notice: Beacon CRM Cyber-Security Incident

5 August 2026

MCR Pathways was informed on Monday 03 August by Beacon CRM, a third-party provider, that it had experienced unauthorised access to its systems.

Beacon has confirmed that copies of database backups were made and were likely downloaded by an unauthorised third party. As it is unlikely to establish exactly which information or individual records were involved, we are taking a precautionary approach and treating all information and attachments held in MCR Pathways’ Beacon account as potentially affected. While this information was encrypted, Beacon’s cyber-security specialists have advised that it is possible it could have been decrypted before being copied.

The incident was contained within Beacon’s systems. Linked services will only be reconnected once the relevant security checks have been completed. Beacon has reported the incident to the Information Commissioner’s Office and to the relevant authorities. MCR Pathways’ wider IT systems and network were not hacked, and we have no evidence that our other systems were accessed or affected.

We are continuing to work with Beacon to understand the incident and its potential impact. We will provide further communication if new information materially changes our understanding of the situation or the potential risk to individuals.

You can read more about the incident and what it may mean for you in our Frequently Asked Questions.

What are we doing?

We take our responsibility to protect personal information extremely seriously.

We began our investigation promptly on 3 August 2026, the day Beacon informed us of the cyber security incident. Since then, we have:

  • reported the personal data breach to the Information Commissioner’s Office within the required 72-hour period;
  • carried out a detailed review of the information and attachments held in our Beacon account;
  • assessed the possible risks to different groups of people;
  • checked records that may contain more sensitive or private information;
  • replaced all the digital access keys used to connect Beacon with our other systems;
  • temporarily disconnected linked services while their connections were reviewed and secured;
  • reviewed access to our account and our relevant internal security arrangements; and
  • continued to seek information and assurances from Beacon as its investigation develops.

What MCR Pathways information may have been involved?

We have undertaken a detailed review of the information MCR Pathways holds in Beacon. Because Beacon is unlikely to establish which individual records were downloaded, we are taking the precautionary approach of treating all information and attachments held in our Beacon account as potentially involved.

The information varies depending on how someone has engaged with us. It may include:

  • names and contact details, such as email addresses, telephone numbers and postal addresses;
  • information about a person’s relationship with MCR Pathways, such as whether they are a donor, fundraiser, event participant, or newsletter subscriber;
  • donation information, including donation dates, amounts and Gift Aid declarations;
  • fundraising and event participation;
  • communications and contact preferences; and
  • files attached directly to a Beacon record, where applicable.

For a small number of people, the information may also include a date of birth or personal information provided as part of a fundraising-event application. We are reviewing those records separately and will contact individuals directly where appropriate.

The information involved is not the same for everyone.

Importantly, MCR Pathways does not store any of the following in Beacon:

  • bank-account or payment-card information;
  • passwords or authentication credentials;
  • passport or driving-licence information;
  • National Insurance numbers; or
  • identified young people’s case, mentoring or safeguarding records.

Young people’s case, mentoring and safeguarding information is held in separate systems and is not part of the affected Beacon database.

What should you do?

We are making people aware of the incident so that they can remain vigilant.

Contact information and knowledge of someone’s relationship with MCR Pathways could potentially be used to make a phishing message or fraudulent approach appear more convincing.

Please be cautious about:

  • unexpected emails, telephone calls or messages claiming to be from MCR Pathways, Beacon CRM or a fundraising platform;
  • links or attachments in unexpected messages;
  • requests for passwords, security codes, personal information, banking details or payment-card information; and
  • unexpected requests to make a donation or payment.

MCR Pathways will never ask you to provide a password or security code. If you receive an unexpected or unusual communication claiming to be from us, please verify it using the contact details published on our official website rather than replying directly or using contact information contained in the message.

Advice about suspicious communications is available from the National Cyber Security Centre. Suspected fraud can be reported to Action Fraud.

You can read more about the incident and what it may mean for you in our Frequently Asked Questions guide.

Contact us

We understand that news of a data-security incident can be concerning, and we are sorry that information entrusted to MCR Pathways may have been involved.

If you have questions or concerns about this incident or the information MCR Pathways holds about you, please contact:

Colin Adam – Data Protection Lead
Email: incident@mcrpathways.org

You might also like

Back to News