6th August 2026
We are writing to let supporters know about a data security incident affecting Beacon, the customer relationship management system we use to hold our contact records.
No bank account or payment card details were held in this system. Donations made to us through Stripe, GoCardless or PayPal are handled entirely by those providers, and Beacon has confirmed there is no evidence that payment information held by payment processors was affected.
We are not aware of any misuse of anyone’s information. We are telling you because we would rather you heard it from us.
What happened
In late July 2026, Beacon was the target of a cyber-attack. Someone gained unauthorised access to Beacon’s systems and took copies of their databases. Beacon has engaged external cyber-security specialists, has reported the incident to the Information Commissioner’s Office and to the police, and its investigation is continuing.
The attack was on Beacon’s own systems and was not directed at Every Casualty Worldwide. Beacon provides its software to over 1,000 UK charities, and the incident is likely to affect many of them. It did not involve any failure of our own systems or accounts.
What information was involved
Beacon has advised its customers to assume that everything held in their accounts was copied. For supporters and donors, the information we hold in this system may include:
- Name
- Postal address
- Email address
- Telephone number
- Record of donations and contact with us
- Gift Aid declaration status
If you have never donated to us or been in contact with us, we will not hold a record for you and you are not affected. Anyone else whose information was held is being contacted by us directly.
What we have done
- Secured our account, and revoked and replaced all system access keys
- Established what information was held and who it relates to
- Carried out a formal assessment of the risk to the people affected
- Reported the incident to the Information Commissioner’s Office
- Gained approval from our board to submit a serious incident report to the Charity Commission
- Continued to press Beacon for further information as its investigation develops
What we suggest you do
There is nothing you need to do urgently, and we are not aware of any misuse of anyone’s information. As a sensible precaution:
- Be cautious about unexpected emails, calls or messages that mention Every Casualty Counts (or our current legal name, Every Casualty Worldwide). Whoever holds this information knows there is a connection between you and us, which makes it easier to write something convincing
- Do not click links or open attachments in messages you were not expecting
- Only trust emails from the domain “everycasualty.org”, as opposed to something designed to look very similar. Email us at to check if you are unsure
- We will never ask you for passwords, verification codes or payment details by email. If you receive a message that does, it is not from us
If you are ever unsure whether something is genuinely from us, please contact us and ask. We would much rather answer than have you take a risk.
More information
We are sorry this has happened. You trusted us with your details and you were entitled to expect them to be safe, and the fact that the failure occurred at a company we rely on does not change our responsibility to you.
Beacon has published information about the incident on its own website. If our understanding changes in any way that affects you, we will update this page and contact anyone affected.
If you have any questions at all, please contact us. Thank you for your understanding.
Craig Grant, Senior Operations Manager, Every Casualty Counts


