Statement Regarding Beacon CRM Data Breach and Information for Supporters
On Monday, 3 August, Plant Your Future was notified of a security incident involving Beacon CRM, the third-party CRM system we use to store details about our supporters and donors. Beacon CRM have informed us that their systems were accessed by an unauthorised party using compromised credentials. They are still investigating this incident and will provide more information as soon as this is available.
We know this news may cause concern, and we offer our sincere apologies. Protecting the privacy and security of your personal data remains a priority for us.
While the full scope of the breach is still being investigated, we will provide additional updates as soon as clear information becomes available.
Incident details:
On Wednesday, 29 July 2026, Beacon CRM identified a cyber-security incident on their platform and promptly brought in external security specialists to secure their environment and conduct a full investigation.Current findings indicate that unauthorized parties used compromised login credentials to access Beacon CRM’s system and download copies of database backups.Beacon CRM alerted its customers, including Plant Your Future, to this breach on Monday, 3 August. More details are available in Beacon CRM Security Incident FAQ: https://www.beaconcrm.org/incident-faqs
Compromised data:
While the investigation proceeds, we want to be transparent about the types of details managed within our Beacon CRM database, which may include:
- Full name
- Postal address
- Contact details (email address and phone number)
- Donation history
Financial information, payment card details, or bank account information has NOT been compromised, as Plant Your Future does not store this information within Beacon CRM.
Next steps:
While we have seen no evidence indicating that any compromised information has been misused, as a protective measure we advise you to:
- Be cautious of unexpected emails, phone calls, or messages claiming to be from Plant Your Future or other organisations.
- Avoid clicking links or downloading attachments from unfamiliar or unverified sources.
- Never share passwords, security codes, or banking details in response to unexpected contact.
Refer to the National Cyber Security Centre data breaches guidance for more information: https://www.ncsc.gov.uk/guidance/data-breaches
Plant Your Future deeply regrets this incident happened and we are following preventative measures to maintain your data safe. If you have any questions, please contact Gelsey Bennett, Managing Director: gelseybennett@plantyourfuture.org.uk.