Notice of Cyber Security Incident Affecting Beacon CRM
At HorseWorld, protecting the personal information of our supporters is extremely important to us. We are therefore writing to make you aware of a cyber-security incident involving Beacon CRM, a trusted third-party provider that we use to manage our supporter database.
Beacon has informed us that it recently experienced unauthorised access to its systems. Their investigation is ongoing with the support of specialist cyber-security experts, and they are providing us with regular updates as more information becomes available.
Based on the information currently available, it is possible that some of the personal information held within Beacon may have been accessed by an unauthorised party. At this stage, there is no evidence that any personal information has been misused.
What information may be affected?
The information held within Beacon may include:
- Name
- Postal address
- Email address
- Telephone number
- Donation history
- Gift Aid declaration (where applicable)
Importantly, HorseWorld does not store payment card details or bank account information within Beacon, and Beacon has confirmed that banking details have not been accessed.
What HorseWorld is doing
As soon as we were informed of the incident, we began working closely with Beacon while they continue their investigation.
We have also:
- Reviewed our systems and integrations.
- Assessed the potential risks to individuals.
- Documented the incident in line with our data breach procedures.
- Considered and fulfilled our regulatory obligations, including notifying the Information Commissioner's Office (ICO).
- Continued to monitor developments as Beacon's investigation progresses.
Beacon has also reported the incident to the ICO and is working with specialist cyber-security experts to understand exactly what happened and whether any personal information has been affected.
What you should do
At present, there is no action you need to take. However, as a precaution, we recommend that you:
- Remain cautious of unexpected emails, text messages or telephone calls claiming to be from HorseWorld.
- Avoid clicking on links or opening attachments unless you are confident they are genuine.
- Never disclose passwords, verification codes or financial information in response to unsolicited communications.
- Report any suspicious emails that appear to come from HorseWorld.
Please remember that HorseWorld will never ask you to provide passwords, banking details or payment information by email or over the telephone.
Keeping you informed
We understand that news like this may be concerning, and we sincerely apologise for any worry this incident may cause.
We are committed to keeping our supporters informed. As Beacon's investigation continues, we will provide further updates if we receive any new information that affects you.
If you have any questions or concerns, please contact us at info@horseworld.org.uk.
-
Beacon Data Breach - Answers to questions you may have
-
What happened?
On Wednesday 29 July 2026, Beacon CRM, a third-party provider used by HorseWorld and many other charities to manage supporter information, became aware of a cyber-security incident affecting its systems.
Beacon immediately engaged specialist cyber-security experts to investigate and secure its systems. Their current understanding is that compromised credentials were used to gain unauthorised access and copies of database backups may have been taken.
HorseWorld was informed of the incident by Beacon on Monday 3 August 2026.
-
What information may have been involved?
Based on the information currently available, it is possible that some of the personal information held within Beacon may have been accessed.
This may include:
- Your name
- Postal address
- Email address
- Telephone number
- Donation history
- Gift Aid declaration (where applicable)
Importantly, HorseWorld does not store payment card details or bank account information within Beacon, and Beacon has confirmed that banking details have not been accessed.
-
Has my information been misused?
At this time, we have no evidence that your personal information has been misused.
Beacon's investigation is still ongoing, and we will contact affected individuals if we receive information indicating that further action is required.
-
Was HorseWorld hacked?
No. The incident occurred within the systems of Beacon CRM, a third-party provider used by HorseWorld and many other charities to manage supporter information. There is no evidence that HorseWorld's own systems were compromised.
-
What is HorseWorld doing?
Protecting your personal information is extremely important to us.
Since being notified of the incident, we have:
- Worked closely with Beacon while they investigate the breach.
- Reviewed our systems and integrations.
- Assessed the potential risks to individuals.
- Recorded the incident in accordance with our data breach procedures.
- Considered and fulfilled our legal obligations under data protection law, including notifying the Information Commissioner's Office (ICO).
- Continued to monitor the situation as Beacon's investigation progresses.
Beacon has also reported the incident to the ICO and is working with specialist cyber-security experts throughout the investigation.
-
What should I do?
There is no action you need to take immediately.
However, we recommend that you:
- Remain vigilant for unexpected emails, telephone calls or text messages claiming to be from HorseWorld.
- Be cautious before clicking on links or opening attachments in unexpected communications.
- Never share passwords, verification codes, banking details or other financial information in response to unsolicited requests.
- Report any suspicious communications that appear to come from HorseWorld.
HorseWorld will never ask you to provide passwords, banking details or payment information by email or over the telephone.
-
Are my payment details affected?
No.
HorseWorld does not store payment card details or bank account information within Beacon, and Beacon has confirmed that banking details have not been accessed.
-
Why are you contacting me if there is no evidence of misuse?
We believe it is important to be open and transparent with our supporters.
Although we have no evidence that any personal information has been misused, we wanted to make you aware of the incident so that you can remain vigilant while Beacon's investigation continues.
-
Will HorseWorld provide further updates?
Yes.
We are receiving regular updates from Beacon and will continue to review any new information they provide. If we learn anything that affects you, we will contact you as soon as possible and update this page where appropriate.
-
Who can I contact if I have questions?
If you have any questions or concerns, please contact us at:
Email: info@horseworld.org.uk
-
What happened?