Data Security Incident – Frequently Asked Questions

Please see below for full information relating to the Beacon Data Security Incident.

This week, we were informed of a data security incident involving Beacon, a third-party service provider that processes supporter data on our behalf.

The data held by our charity within the Beacon system does not include any bank account or credit/debit card information. However, it may include personal information such as contact details, donation history and other information that supporters have shared with us.

We are one of more than 1,000 charities affected by this incident. As a result, some individuals may receive similar notifications from other organisations where their information is also held within the Beacon system.

We are contacting those who may have been affected directly, and have published answers to frequently asked questions below. While there is currently no evidence that any personal information has been misused, we encourage everyone to remain vigilant and follow the guidance provided.

What happened?

On 3 August 2026, our third party data processor, Beacon, who provides our supporter database system, informed us of a cyber-security incident affecting their systems.

After discovering the attack, Beacon’s team immediately conducted a thorough investigation with the support of an independent cyber forensics’ expert and law enforcement.
As soon as we were told, we took immediate steps to contain the risk, secure our own systems, and begin an investigation with the processor. We have reported this to the Information Commissioner’s Office (ICO) and the Charity Commission.

What information may be affected?

Based on our current investigation, the following information relating to you may have been involved:
• Your name and email address
• Postal address and phone number
• Donation history (dates/amounts)
• Date of birth
• Gift Aid information, including confirmation of your UK taxpayer status and any Gift Aid declarations
• Transaction information, including references relating to donations or other payments made to North Yorkshire Hospice Care
• Employment or volunteering information that you have shared with us, such as details of your employer or volunteer role
• Health information that you have voluntarily shared with us for fundraising or supporter purposes. This does not include clinical records or information held within our patient care systems
• Bereavement-related information, including records associated with donations made in memory of a loved one or donations linked to our bereavement services. This does not include client records or any information held within our Just’B’ service.
• Information relating to children and young people (under 18), where they have attended or participated in our events

What this means for you

While we have no evidence that your information has been misused, we recommend remaining vigilant for any unexpected emails, text messages or phone calls claiming to be from us (North Yorkshire Hospice Care or Saint Michael’s Hospice, Herriot Hospice and JustB) or asking for personal or financial information. We will never ask you to provide sensitive information by email, telephone or text message.

• Be cautious of unexpected emails, texts or calls asking for personal details or payments
• Do not click links or open attachments from unknown senders
• Consider updating passwords on any accounts where you reused the same password
• Monitor bank and credit card statements for unusual activity
• If you notice suspicious activity, or suspected identity theft, contact your bank and report it to Action Fraud (www.actionfraud.police.uk).

What we’re doing

We take data security seriously. In addition to containing the incident, we have:
• Required the processor to provide a full forensic report and timeline
• Reviewed our contracts and data processing agreements to strengthen security obligations

How to get help or ask questions

We understand you may have concerns. You can:

• Read our FAQs below which will be updated via this page.
• Contact our dedicated helplines on 01609 777413 (option 2) or 01423 878628 or email info@saintmichaelshospice.org (Mon–Fri, 9 am to 5 pm)
• If you wish, you can also contact the ICO directly on 0303 123 1113 or via their website.

As we wanted to communicate this news to you as soon as possible, our apologies that this letter is not bespoke to you, but if you have a direct relationship with one of our team members, please feel free to contact them direct if you would like to discuss this through.

Thank you for your continued support. We are committed to keeping your information safe and will provide further updates if our investigation reveals anything new that affects you.

Read more

Frequently Asked Questions (FAQs)

1. What happened?

On 3 August 2026, our third-party data processor, Beacon, informed us of a security incident affecting systems they operate on our behalf. As soon as we were told, we took steps to contain the risk, secure our own systems, and begin an investigation with the processor. We have reported this to the Information Commisioner’s Office (ICO) and the Charity Commission.

2. What information of mine might be affected?

Based on our current investigation, the following information relating to you may have been involved:

  • your name and email address
  • postal address and phone number
  • donation history (dates/amounts)
  • Date of birth.
  • Gift Aid information, including confirmation of your UK taxpayer status and any Gift Aid declarations.
  • Transaction information, including references relating to donations or other payments made to North Yorkshire Hospice Care.
  • Employment or volunteering information that you have shared with us, such as details of your employer or volunteer role.
  • Health information that you have voluntarily shared with us for fundraising or supporter purposes. This does not include clinical records or information held within our patient care systems.
  • Bereavement-related information, including records associated with donations made in memory of a loved one or donations linked to our bereavement services.
  • Information relating to children and young people (under 18), where they have attended or participated in our events.

3. Why am I being told if the breach was with your supplier?

Under UK GDPR, we are the “data controller” and remain responsible for your data, even when it’s processed by a third party on our behalf.  When a processor has a breach, they must tell us without undue delay, and we must assess the risk, report to the ICO where required, and inform affected individuals if there is a high risk to their rights and freedoms.

4. Has my payment or bank information been compromised?

No. Payment card and bank details are held by our separate payment provider and were not stored on the affected system.

5. Has my data been misused?

At this time, we have no evidence that your information has been misused.  However, any breach can increase the risk of phishing emails, scam calls, or identity fraud, so we’re advising supporters to be extra vigilant.

6. What should I do to protect myself?

Practical steps you can take now:

  • Be cautious of unexpected emails, texts or calls asking for personal details or payments
  • Do not click links or open attachments from unknown senders
  • If you reuse passwords, consider changing them and enabling two‑factor authentication where available
  • Monitor bank and credit card statements for unusual activity
  • If you suspect fraud, contact your bank and report it to Action Fraud (https://www.actionfraud.police.uk)

7. How did this happen?

Our processor is investigating the root cause.  At this stage, we can share that Beacon believe that encrypted copies of their back-up systems were likely downloaded.  We will update this FAQ if our investigation reveals anything new that affects you.

8. What are you doing to fix it and prevent it from happening again?

We are taking this incident very seriously and are committed to keeping your data safe.

  • Required the processor to provide a full forensic report and timeline to understand what happened and to ensure additional safeguards are implemented to ensure this doesn’t happen again
  • Reviewed our contracts and data‑processing agreements to strengthen security obligations

9. Will this affect my donations or Gift Aid?

No. Your donation records and Gift Aid declarations remain secure and unchanged.  If we need to contact you about any administrative matter, we will do so via official channels only.

10. How do I know a message is really from you?

We will only contact you about this incident from official email addresses ending in @saintmichaelshospice.org, @herriothh.org.uk, justb.org.uk or @hospice-care.org.

We will not ask you for passwords or payment details by email.  If you’re unsure, do not proceed and contact us directly.

11. Who do I contact if I have questions or concerns?

  • Read this FAQ:
  • Contact our dedicated helplines:  01609 777413 (option 2) or 01423 878628 or email info@saintmichaelshospice.org (Mon–Fri, 9 am to 5 pm)or email info@saintmichaelshospice.org (Mon–Fri 9 am to 5 pm)
  • Contact the ICO directly on 0303 123 1113 or via their website if you wish.
Read more