On Wednesday 29 July 2026, Beacon, our CRM software provider, became aware that they may have experienced a cyber-security incident. They notified us of this on Monday 3 August 2026.Â
We like many other charities who use Beacon CRM could have been affected, so you might have already also heard about this.Â
We store some organisational data on Beacon CRM, so it is possible some data from our members and other subscribers may have been involved.Â
Beacon’s current understanding is that compromised credentials were used to gain access to their systems, and that copies of their database backups were made. Whilst the copying or taking of this data has not yet been confirmed, the evidence so far suggests copies were likely downloaded. There is currently no evidence of further leaks or dissemination.Â
The data that may have been affected includes names, email addresses, phone numbers, job titles, and workplace addresses, but does not include any financial information. If people have shared access information with us for our online or in person events, it may also have been affected.Â
Beacon has taken immediate action to mitigate this, and is now:Â
- Conducting a thorough forensic investigation with external cyber-security specialists;Â
- Working with law enforcement and relevant regulators as required;Â
- Carrying out ongoing monitoring for any misuse of data – so far nothing of concern has been found;Â
- Completing precautionary security measures across their systems.Â
We take the security of your data very seriously and are reporting this matter to the Information Commissioner’s Office (ICO).
David Simpson, Chief Technology Officer at Beacon CRM said in the initial incident notice: “I’m so sorry to be sharing this news. We know this will be concerning, and we’re taking it seriously.” and The Exhibitions Group would like to extend this apology to our members and subscribers for any inconvenience and worry this incident may cause.
If you have any questions, please do contact our Data Protection Officer