Updated – 4th August 2026 – 18:04
Held In Our Hearts has been informed that Beacon CRM, our membership and customer record platform provider, has experienced a cyber-security incident involving unauthorised access to its systems.
Beacon believes that copies of its database backups may have been downloaded. This means that personal information held on the platform, including names, email addresses and other contact details, may have been accessed.
Please note that credit card and payment details have not been compromised.
We are making our community aware of the incident so that they can remain vigilant.
We are advising everyone to be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.
Beacon is investigating the incident with external cyber-security specialists and is working with the relevant authorities. You can read their full statement and follow progress here – Incident FAQs .
We have undertaken all recommended security steps advised by Beacon in the Security Incident Response Guide and have reported this incident to the Information Commissioner, as expected in instances such as these. Our Chair and Board have also been made aware. We will provide further information should this become necessary.
We know this can cause concern particularly as it may relate to personal data, therefore anyone with questions or concerns should email info@heldinourhearts.org.uk where a dedicated member of the team will review your concerns and we will get back to you.
Nicola Welsh
CEO


