*Last updated 12/08/26 – 16:52*
New Horizon Youth Centre takes its responsibility to protect sensitive personal information very seriously.
On 3 August 2026, we were informed that Beacon CRM, which processes fundraising and supporter information on our behalf, had experienced a cyber-security incident.
What we know so far
Beacon CRM have updated us (as of 12 August 2026), confirming their earlier suspicion that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor.
Beacon has also identified that the probable root cause of this incident was a compromised AWS access key. The earliest malicious activity observed occurred on 27 July 2026 at 01:20:16 UTC and lasted for approximately 1 hour and 27 minutes.
Beacon CRM has established that copies of its database backups were made. This means that personal contact information, held in our Beacon account before 5am on 27 July 2026 may have been accessed. There is no evidence that any card details or bank account information has been compromised.
Who will this affect?
On Beacon we store information that our donors, supporters and partners share with us, this may include names, contact details and address, organisation or employer, correspondence and communication preferences and, where relevant, information about donations, Gift Aid or your wider relationship with us. We are awaiting further updates from Beacon, however they have noted that they may never be able to let us know the specific substance of the data that has been breached.
Beacon has said there is currently no evidence that any information has been published online or that a ransom demand has been made. Its investigation is continuing with external cyber-security specialists. You can read more about what Beacon has said about the incident here: https://www.beaconcrm.org/incident-guidance
As personal data has been breached, we have an obligation under the Data Protection Act (2018) to report this both to the Information Commissioners Office and to those individuals affected. In the interest of full transparency, we therefore wanted to communicate this widely at the first possible opportunity.
The clearest current risk is that someone could use personal information to make a fraudulent email, telephone call or message appear more convincing. We ask that all of our donors be particularly cautious about unexpected communications referring to New Horizon, your donations or your relationship with us. Do not click unexpected links, or provide passwords, security codes, banking information or other personal details.
What we are doing now
Our immediate priority has been to notify data subjects affected by the breach so that they can take appropriate remedial steps. We have also begun taking further precautionary action, including securing access to our Beacon account, resetting passwords and disconnecting applications and integrations with Beacon. In doing so, we are following guidance from the Information Commissioner’s Office and the Charity Commission and meeting our regulatory reporting requirements.
You can read our full Privacy Policy on our website here: https://nhyouthcentre.org.uk/privacy/
What you can do now
We know that loss of data can be deeply unsettling, we apologise unreservedly for the concern this incident may cause. We will provide further information to any donors whose information may have been accessed as soon as Beacon’s, or our own, investigation identifies any material changes to the position outlined above. We understand that this may affect trust in us, and if you have a recurring donation you wish to change your preferences on, please do get in touch.
We will keep this public statement updated as we receive new information.
If you receive a communication that appears suspicious, please contact us independently on 020 7344 5560 or at [email protected]. Please do not use contact details or links contained within the suspicious message itself.
FAQs
1.Why does New Horizon use a CRM? Why did we choose Beacon?
It is standard procedure for charities to use a CRM (Customer Relationship Manager) to manage and monitor their communications with and support from the public. This is to keep all of this information in one place securely and ensure consistency. We transitioned to Beacon in 2023 after reviewing five different CRM options. We completed a thorough due diligence of their security measures, in line with our GDPR, Privacy and Data Compliance policies. Beacon are one of the most popular CRM providers for charities and they have confirmed that all of their customers are affected. They are in communication with us and their other customers as the breach unfolds and will continue to update this page as the situation develops.
2. What does New Horizon do to protect the data it collects?
New Horizon has rigorous policies and procedures in place to protect the data and privacy of our supporters, staff and service users. We have several policies in place covering topics such as GDPR, Data Compliance & Privacy, which are reviewed every two years by our executive and Board of Trustees. Our Data Protection Officer and Chief Operating Officer regularly review our compliance in these areas, and we are Cyber Essentials Certified. We are completely committed to maintaining the highest standards and are conducting a full investigation into this breach of a subcontracted organisation.
3. Will you continue to use Beacon in the future?
Our top priority is investigating the breach at Beacon and ensuring anyone affected is informed and protected. Upon completion of the investigation, we will review our future data needs in line with our policies and make a decision about the right donor CRM for New Horizon.
4. Why have I received an email about this when I’ve unsubscribed to New Horizon?
If you had previously requested to be unsubscribed from communications from New Horizon, you will have been removed from future communications but your contact details will have remained on our system in line with GDPR regulations. Therefore we still needed to contact you in order to comply with our requirements regarding the handling of your personal data under General Data Protection Regulation (GDPR). If you have previously unsubscribed from our mailing list, we can confirm that this is not a sign of us re-subscribing you, and we of course will abide by your wish not to be contacted further by New Horizon Youth Centre.