Take the Leap for BDA Youth: Skydive Fundraiser 2026
Members of the BDA Youth Committee, BDA staff and supporters are taking to the skies to raise funds…
31 July 2026
Current information
Information about the Beacon CRM incident
This page provides information for people whose email address is linked to one or more records held by the British Deaf Association in Beacon CRM.
Last updated: 5 August 2026
Information about the Beacon CRM incident
On 3 August 2026, Beacon informed us that it had experienced a cyber-security incident. Beacon has confirmed that an unauthorised third party gained access to its systems, copies of customer database backups were made, and the available evidence suggests that those copies were likely downloaded.
Beacon has advised its customers to assume that information stored within their accounts, including attachments, may have been involved. There is currently no evidence that the information has been published or misused.
What information may have been involved?
The information held about each person varies. Depending on how you have interacted with the BDA, it may have included:
- your name and contact details;
- membership information;
- donation, payment and Gift Aid records;
- event attendance, dietary or accessibility information;
- communication preferences;
- information you provided about disability, health or whether you identify as Deaf, DeafBlind, hard of hearing or hearing;
- award nomination information; and
- notes or attachments connected with your record.
Not all of these categories will apply to everyone. Beacon has said there is no evidence that payment card details were compromised.
At present, neither Beacon nor the BDA can confirm exactly which individual records were downloaded or viewed, due to the type of cyber-attack experienced.
What are the possible risks?
The information could potentially be used to make phishing, impersonation or attempted fraud more convincing. The disclosure of personal or sensitive information could also cause distress or a loss of privacy.
There is currently no evidence that this has happened, but we are informing you so that you can remain alert and take sensible precautions.
What have we done?
- reported the incident to the Information Commissioner’s Office;
- reviewed the types of information held in our Beacon account and assessed the potential risks;
- reviewed and secured the integrations and access credentials connected with Beacon;
- followed Beacon’s immediate security recommendations; and
- continued to work with Beacon and monitor its investigation.
Beacon has told us that it has contained the incident and is continuing its investigation with external cyber-security specialists.
What should you do?
You do not need to take any immediate action, but we recommend that you:
- be cautious of unexpected emails, telephone calls, text messages or social media messages;
- be particularly careful about messages claiming to be from the BDA, Beacon or an organisation connected with a donation or event;
- do not provide passwords, payment information or other personal details in response to an unexpected message;
- do not click links or open attachments unless you are confident that the message is genuine; and
- contact us directly if you receive anything suspicious claiming to be from the BDA.
More information
Further information, including an FAQ and a BSL version of this notice, is available here:
We are very sorry that this has happened and for any concern it may cause. It is our understanding that Beacon is widely used by a large number of charities and organisations which have been affected by this cyber security incident.
For questions about the incident, please contact:
We will update the information on our website if Beacon provides any significant new findings.
Questions and answers
Frequently asked questions
Select a question below to read the answer.
Why did I receive an email from the BDA?
You received the email because your email address is linked to one or more records held by the BDA in Beacon CRM.
Beacon is the system we use to manage information about members, supporters, donors, event attendees and other contacts.
Does this mean my information was definitely downloaded?
Not necessarily. However, Beacon has confirmed that copies of customer database backups were made and that the available evidence suggests those copies were likely downloaded.
Neither Beacon nor the BDA can currently confirm exactly which individual records were downloaded or viewed. Beacon has therefore advised customers to assume that information stored in their accounts, including attachments, may have been involved.
What information might have been involved?
The information varies depending on how you have interacted with the BDA. It may have included contact details, membership information, donation or Gift Aid records, event information, communication preferences, award nominations, notes or attachments.
Some records may also have contained information about disability, health, accessibility requirements or whether someone identifies as Deaf, DeafBlind, hard of hearing or hearing. Not all categories apply to every person.
Were payment card details compromised?
Beacon has said there is no evidence that payment card details were compromised.
Has the information been published or misused?
There is currently no evidence that the information has been published or misused.
We are informing people because the information could potentially be used to make phishing, impersonation or attempted fraud more convincing.
Do I need to take any immediate action?
You do not need to take any immediate action. We recommend remaining alert for unexpected emails, telephone calls, text messages or social media messages.
Be especially careful about messages claiming to be from the BDA, Beacon or an organisation connected with a donation, event or membership.
Why can the BDA not identify exactly which records were involved?
The incident involved copies of database backups. Because of the type of cyber-attack experienced, neither Beacon nor the BDA can currently confirm which individual records within those backups were downloaded or viewed.
What has the BDA done in response?
We have reported the incident to the Information Commissioner’s Office, reviewed the information held in our account, assessed the potential risks and secured the integrations and access credentials connected with Beacon.
We have followed Beacon’s immediate security recommendations and will continue to monitor its investigation.
What should I do if I receive a suspicious message?
Do not click any links, open attachments or provide personal, password or payment information.
Contact the BDA separately using an email address or website that you already know is genuine. Suspicious messages claiming to be from the BDA can be sent to dataprotection@bda.org.uk .
Will this page be updated?
Yes. We will update this page if Beacon provides any significant new findings that affect the information we have given to you.
Protect yourself
How to spot a suspicious message
A scam message may look convincing and could include information that is correct. Take extra care if you notice any of the following.
Unexpected contact
The message arrives unexpectedly and asks you to respond, make a payment, confirm an account or provide personal information.
Pressure or urgency
The sender tells you to act immediately, warns that something bad will happen or tries to stop you checking the message.
An unusual sender address
The display name may say “British Deaf Association”, but the actual email address may be unfamiliar, misspelt or unrelated to the BDA.
Links and attachments
The message asks you to follow a link, download a file or open an attachment that you were not expecting.
Requests for sensitive information
The sender asks for a password, bank details, payment-card information, security code or other private information.
Information that sounds familiar
A scammer may mention a real event, donation, membership or organisation to make the message appear genuine. Correct details do not always mean the message is safe.
What to do
- Stop and check. Do not respond, click a link or open an attachment.
- Contact the organisation separately. Type its website address into your browser or use contact details that you already know are genuine.
- Tell the BDA. Send suspicious messages claiming to be from us to dataprotection@bda.org.uk .
- Report suspicious emails and texts. Forward suspicious emails to report@phishing.gov.uk and suspicious text messages to 7726.
- Act quickly if money is involved. If you have shared bank details or lost money, contact your bank immediately. In England, Wales and Northern Ireland, report fraud to Report Fraud . In Scotland, contact Police Scotland by calling 101.
Official information
Further information
The following external pages provide further information about the incident, phishing and protecting personal information.
Questions or concerns?
Contact the BDA Data Protection team if you have a question about this incident or receive a suspicious message claiming to be from the BDA.