Skip to main content

Your web browser is out of date. Please update it for greater security, speed and the best experience on this site.

Choose a different browser

Beacon CRM incident

Wall-mounted sign with the logo for the Centre for Sustainable Energy
4 August 2026

Yesterday, there was a security incident involving Beacon, the CRM system used by the Centre for Sustainable Energy (CSE) to manage our contact data.

Yesterday, there was a security incident involving Beacon, the CRM system used by the Centre for Sustainable Energy (CSE) to manage our contact data.

It is important to note that this incident is not unique to the Centre for Sustainable Energy and affects organisations across the charitable sector that use Beacon’s CRM platform. We’re sorry to be sharing this news. We know it may be worrying, and we want to be as clear and honest as possible about what happened and what it means for you.

What happened?

Beacon recently identified a security incident affecting its systems. Following notification from Beacon, we conducted a review of the information stored in our Beacon account to determine whether any personal information relating to our contacts may have been affected.

What information was involved?

Our review indicates that the following categories of personal information held in Beacon may have been involved in this incident:

The information that may have been accessed does not include bank account details or card numbers. It cannot be used to access bank account or make payments.

What are the potential risks?

It is possible that personal information held within Beacon was accessed without authorisation. Depending on the information involved, this could increase the risk of:

We have no evidence that the information has been misused. But we encourage our contacts to stay vigilant and take extra care when responding to unexpected emails, phone calls or messages.

What actions have been taken?

Both CSE and Beacon have taken steps to address the incident and reduce the risk of further unauthorised access. You can read about Beacon’s activities here: Incident Guidance.

As the data controller CSE has taken the following actions:

We are making our contacts aware of the incident so that they can remain vigilant. Contacts should be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.

Further information

Keeping personal information safe is something we take seriously, and we are committed to being open as the situation develops.

If you have any questions or would like further information, please contact privacy@cse.org.uk. You can also find further information, including FAQs here.

Share this: