13th August 2026
Beacon CRM Update
Beacon have published a new update on their website listing more details about the incident and how it occurred. They write: “This update confirms their [the external security experts] assessment that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor.” You can read their full report here: https://www.beaconcrm.org/incident
We are continuing to review this situation as more information becomes available and will make any update available here. We ask supporters to be very vigilant with emails and phone calls that may pretend to be from SIM. If you are in any doubt please email [email protected]. We will never ask you for bank details by email or over the phone.
5th August 2026
This information was sent to all who are on our database. If there are any further updates, they will be written here in due course.
Beacon CRM Update
We are writing to provide an update regarding a cyber-security incident involving Beacon, our external database provider which we use to manage enquiries, supporter interactions, communications and bookings for events.
The incident may have involved some of the personal information we hold about you. We take the security of your information very seriously, and we want to provide you with more information here.
What happened?
On Wednesday, 29th July 2026, Beacon, our CRM software provider, became aware that they may have experienced a cyber-security incident. They immediately engaged external cybersecurity experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of their database backups were made and, from the evidence currently available, were likely downloaded.
We were notified by Beacon that they discovered this incident on Monday 3rd August.
What information has been affected?
Out of an abundance of caution, we are assuming that data stored in our Beacon account may have been accessed. The information potentially accessed includes contact details (name, address, email address, phone number), a history of donations to SIM UK and event attendees.
Beacon does not store payment card details or bank account information, so these were not compromised.
What is being done?
On discovering the incident, Beacon immediately engaged external cybersecurity experts to secure the system and prevent any further unauthorised access. They are continuing to investigate to understand exactly what happened, and we will update you if we learn of anything significant that changes what we have already communicated here.
As soon as we heard from Beacon, we took steps to secure our own Beacon account, as well as reporting the incident to the Information Commissioner’s Office (ICO) and the Charity Commission of England and Wales and we are following all official guidance.
Beyond the immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident. We are confident that our Beacon account is secure, and we will continue to use the system as usual.
What should I do?
You do not need to take any direct action; we simply want to let you know what has happened.
There is currently no evidence that your information has been published or misused in any way, and we are not aware of any fraud or harm resulting from this incident.
However, please remain alert to suspicious emails, telephone calls or social media approaches that appear to come from SIM UK.
- Be cautious about unexpected requests for money, passwords, banking information or security codes. We will never call you asking for payment, bank details or passwords.
- Do not open unexpected attachments or follow suspicious links.
- Check requests by contacting us through the telephone number or email address on our official website, not by using contact details supplied in a suspicious message.
- Please tell us promptly if you receive a suspicious communication that appears to relate to SIM UK.
Further information
We are very sorry for the concern this incident may cause. Please be assured that we are taking it very seriously.
If you have any questions or need assistance, please contact us at: [email protected]
Thank you for your understanding whilst the incident is being investigated. We are aware that many other Christian and non-Christian charities and their supporters have also been affected. We ask you to pray for wisdom and for the safety of everyone involved.