Important information about a Beacon data breach
Bromley and Lewisham Mencap is letting members, service users, supporters and donors know about a data breach involving Beacon.
Beacon notified Bromley and Lewisham Mencap of the incident on Monday 3 August 2026.
Beacon is the external database system used by Bromley and Lewisham Mencap, and many other charities. We use Beacon to help manage information about members, service users, supporters, donors, fundraisers, activities, bookings and payments.
The data breach happened because someone gained unauthorised access to Beacon’s systems. It was not a breach of Bromley and Lewisham Mencap’s own website or email systems.
Beacon has now told us that a copy of the database holding Beacon customer data, including attachment files, was made and was likely downloaded in a readable format.
Beacon has also told us that it may not be possible to confirm exactly which individual records or attachment files were downloaded.
Because of this, we are treating the matter seriously and working on the basis that information held by Bromley and Lewisham Mencap in Beacon was likely affected.
This may include:
- name and contact details
- activity or event bookings
- records of payments or donations made to us
- fundraising information
- information about support needs, where this has been shared with us
- documents or files attached to Beacon records, where applicable
Please note that our Beacon records do not contain bank account numbers, sort codes, full card numbers or card security details. These payment details are held separately and are not currently known to have been affected.
Beacon has told us that it has taken steps to secure its systems and is working with cyber-security specialists to investigate what happened. Beacon has also told us that it has not identified any ongoing unauthorised access since the incident was contained.
Bromley and Lewisham Mencap has reported the incident to the Information Commissioner’s Office, also known as the ICO. The ICO has confirmed that it does not intend to take any further action at this stage.
We are contacting everyone whose information is held in Beacon because we believe information held by Bromley and Lewisham Mencap in Beacon was likely affected.
We understand that this situation may be worrying, and we are very sorry this has happened.
There is currently no evidence that the information has been shared publicly or misused. However, if information has been accessed, there is a risk that it could be used to contact people unexpectedly or to try to obtain further personal or financial information.
We will update this page if we receive more information from Beacon.
What you can do
You do not need to do anything straight away, but please be careful with unexpected emails, phone calls or text messages.
Please:
- do not click links or open attachments if you are unsure who they are from
- be cautious if someone contacts you unexpectedly and asks for personal or financial information
- contact your bank if you notice anything unusual on your account
- let us know if you receive anything suspicious claiming to be from Bromley and Lewisham Mencap, Beacon, JustGiving, Mailchimp or another organisation linked to us
Bromley and Lewisham Mencap will never ask you for your password or banking security codes by email, text or phone.
If you are unsure whether a message or call is really from us, please contact us directly.
We are here to help
We understand that you may have questions or concerns.
Please contact:
We will share more information when we have it and will update this webpage accordingly. (This page was last updated on Thursday 13 August).
