Last updated – 10:50 on 17/08/2026
Group B Strep Support (GBSS) uses a system called Beacon CRM to keep records of people who support, volunteer with, donate to, campaign with, work with or contact the charity for information or support.
On 3 August 2026, Beacon informed its customers, including GBSS, that it had experienced a cyber security incident. This means someone who should not have had access was able to access Beacon’s systems. Since then, we have been seeking further information from Beacon, taking advice from the relevant regulators and working to understand what information may have been affected.
Importantly, neither Beacon nor nor GBSS has identified any evidence that information downloaded during the incident has been made public, shared or otherwise misused.
This incident was not specific to GBSS. Beacon provides CRM services to more than 1,500 charities and has told its customers that many, potentially all, charities using its system may have been affected. We know this does not make it less concerning for anyone whose information may be involved, but it is important context for understanding what happened.
We understand that this may be worrying, especially for people who have shared personal or sensitive information with us. We are sorry for the concern this may cause, and we will continue to be as open as we can as we understand more.
What happened?
Beacon, the system provider we use to hold our supporter and contact records, has told its customers that it experienced a cyber security incident.
Beacon has advised its customers that its current assessment is that a copy of the database containing customer data, including attached files, was made and likely downloaded by the person or people responsible.
Beacon has said that any information downloaded would have been available in a readable form. It has also said that it cannot tell exactly which records were accessed or downloaded.
At present, Beacon has said it has no evidence that the information has been made public, shared or otherwise misused.
What information could be affected?
The information GBSS holds in Beacon is different for different people. It depends on how someone has been involved with us – for example, whether they have donated, fundraised, volunteered, campaigned, worked with us or contacted us for information or support.
This may include:
- name and contact details (such as email address, postal address and telephone number, where held);
- donation or fundraising records;
- volunteering information;
- emails or other correspondence with GBSS;
- notes relating to requests for information or support.
For some people, records may also include more sensitive information they shared with us when asking for support, information or advocacy.
Beacon has said it cannot tell exactly which records were accessed or downloaded, so we do not yet know exactly whose information was affected.
Importantly, Group B Strep Support does not store bank account details or payment card information in Beacon. We therefore have no reason to believe that any banking, credit, debit or payment card details were accessed through this incident.
What has GBSS done?
Since we became aware of the incident, GBSS has taken steps to understand what happened, report it appropriately and consider what this may mean for people whose information may have been affected. We have:
- started our data breach assessment process;
- asked Beacon for further information;
- reported the incident to the Information Commissioner’s Office (ICO) as a precaution;
- reported the incident to the Charity Commission for England & Wales as a precaution;
- checked what steps GBSS needs to take in response;
- kept a clear record of the decisions and actions we have taken; and
- continued to assess what this may mean for people whose information may have been affected.
What should I do?
At the moment, Beacon has said it has no evidence that the information has been made public, shared or otherwise misused.
However, it is sensible to be cautious. Please be alert to any unexpected emails, messages, texts, phone calls or other contact that:
- claims to be from GBSS;
- mentions information you may have shared with us; or
- asks you to click a link, share personal details or make a payment.
If you receive anything that seems suspicious, do not click on links or share personal information unless you are sure it is genuine.
If you are unsure whether a message really is from GBSS, please contact us using the details below.
Do I need to contact GBSS?
No, you do not need to contact us unless you are worried or have a specific question or concern.
We have published this information so people are aware of what has happened and what steps we are taking.
If we receive new information that changes our understanding of the incident, we will update this page.
Further information
If you have a question or concern about this incident, or if you receive a message that appears to come from GBSS and are unsure whether it is genuine, please contact us:
Email: admin@gbss.org.uk
Phone: 0330 120 0795
Group B Strep Support (GBSS) uses Beacon CRM to keep records of people who support, volunteer with, donate to, campaign with, work with or contact the charity for information or support.
Beacon has told its customers, including GBSS, that it has experienced a cyber security incident affecting its systems. Beacon provides CRM services to more than 1,500 charities and has said that many, potentially all, charities using its system may have been affected.
We want people whose information may be involved to know what has happened, what we currently understand and what steps they can take.
On 3 August 2026, Beacon told its customers that it had experienced a cyber security incident. This means someone who should not have had access was able to access Beacon’s systems.
Beacon has advised its customers that its current assessment is that a copy of the database containing customer data, including attached files, was made and likely downloaded by the person or people responsible.
Beacon has said that any information downloaded would have been available in a readable form. It has also said that it cannot tell exactly which records were accessed or downloaded.
At present, Beacon has said it has no evidence that the information has been made public, shared or otherwise misused.
Beacon has advised its customers that it identified and contained the incident, reset credentials associated with affected systems, engaged independent cyber security specialists to investigate and respond, and implemented additional security monitoring.
Beacon has also stated that, since containing the incident, it has not identified any ongoing unauthorised access to its systems.
Beacon’s investigation remains ongoing. The latest information published by Beacon can be found on its incident page.
The information GBSS holds in Beacon is different for different people. It depends on how someone has been involved with us – for example, whether they have donated, fundraised, volunteered, campaigned, worked with us, attended an event, or contacted us for information or support.
This may include:
Name and contact details
Communication preferences
Donation or fundraising records
Volunteering information
Event registration
Emails or other correspondence with GBSS
Notes relating to requests for information or support.
For some people, records may also include more sensitive information they shared with us when seeking support, information or advocacy or when telling us about the impact of group B Strep.
We do not know.
Beacon has said it cannot tell exactly which records were accessed or downloaded. Because Beacon believes its customer database was likely downloaded, we are treating information held in Beacon as potentially affected.
GBSS does not store bank account details or payment card information in Beacon. We therefore have no reason to believe that any banking or payment card details were accessed through this incident.
At present, Beacon has said it has no evidence that the information has been made public, shared or otherwise misused.
GBSS has not identified any evidence that personal information connected with this incident has been made public or used maliciously.
We will update this page if that changes.
At the moment, Beacon has said it has no evidence that the information has been made public, shared or otherwise misused. However, it is sensible to be cautious.
Please be alert to any unexpected emails, texts, phone calls or messages that:
- claim to be from GBSS;
- Mention information you may have shared with us; or
- Asks you to click a link, share personal details or make a payment.
If you receive anything that seems suspicious, please do not click links or share personal information unless you are sure it is genuine.
If you are unsure whether a message really is from GBSS, please contact us using the details on this page.
When Beacon first told customers about the incident, there was still uncertainty about what had happened and what information may have been affected.
Beacon has since provided a clearer update, including that its customer database was likely downloaded.
After considering this information and speaking with the ICO, we believe it is right to share this update with people whose information may have been affected.
Yes. GBSS reported the incident to the Information Commissioner’s Office (ICO) as a precaution.
We also reported the incident to the Charity Commission for England and Wales as a precaution.
The Charity Commission has said that it does not need further updates about the Beacon incident unless GBSS becomes affected by a specific incident arising from the breach.
We understand that this news may feel especially upsetting for people who have shared personal experiences with us or contacted us for support during a difficult time.
At present, we do not know which individual records were accessed or downloaded, and we have not identified any evidence that personal information has been made public or used.
If you are worried or would like to talk to us about your circumstances, please contact us and we will do our best to help.
If you have a question or concern about this incident, or if you receive a message that appears to come from GBSS and are unsure whether it is genuine, please contact us:
Email: admin@gbss.org.uk
Phone: 0330 120 0795
We will continue to review the situation and update this page if we receive new information that changes our understanding of the incident.




