EMICS home

Statement on Beacon CRM Data Security Incident

05/08/2026

East Midlands Immediate Care Scheme (EMICS) Last updated: 5 August 2026

We are writing to inform our members, volunteers, supporters and partners about a data security incident affecting Beacon CRM (Customer Relationship Management), a third-party software provider we use to manage donations and web form contacts.

What happened

Beacon has confirmed that they identified the incident on Wednesday 29 July 2026. An unauthorised third party gained access to their systems using compromised login credentials. Beacon's investigation, supported by external cyber-security specialists, has found evidence that copies of database backups were made and were likely downloaded by the unauthorised party.

What this means for your data

As a precaution, Beacon has advised all customers to assume that data held within their Beacon account may have been accessed. This may include:

  • Name
  • Contact details (email address and phone number)
  • Address
  • Record of donations or payments made to EMICS
  • Information you have provided to us in connection with our services and activities
  • Date of birth
  • Gender

We want to be clear on payment data: there is currently no evidence that any payment card details have been compromised, and no evidence that data from this incident has appeared for sale or been shared publicly at this time.

Beacon has confirmed that the affected service has now been secured, and there is no perceived risk to anyone currently using the platform.

What we have done

Since being notified, EMICS has:

  • Convened our Board and begun coordinating our response
  • Reported the incident to the Information Commissioner's Office (ICO), reference number IC-549760-P9Q9
  • Reported the incident to the Charity Commission for England & Wales

We are continuing to assess the scope of this incident and will notify any individuals directly if we determine there is a high risk to their rights and interests, in line with our obligations under UK GDPR. We will publish a follow-up update as this work progresses.

What we are asking of you

If you have any concerns, or believe you may have been affected, please contact us at fundraising@emics.org.uk. We will do our best to respond as quickly as possible.

We take the security of the data entrusted to us extremely seriously and are working to understand the full scope of this incident. We will update this page as we learn more.

Support us – Donate

Donate Now