This week, we were informed of a data security incident involving Beacon, a third-party service provider that processes supporter data on our behalf.
The data held by our charity within the Beacon system does not include any bank account or credit/debit card information. However, it may include personal information such as contact details, donation history and other information that supporters have shared with us.
We are one of more than 1,000 charities affected by this incident. As a result, some individuals may receive similar notifications from other organisations where their information is also held within the Beacon system.
We are contacting those who may have been affected directly, and have published answers to frequently asked questions below. While there is currently no evidence that any personal information has been misused, we encourage everyone to remain vigilant and follow the guidance provided.
On 3 August 2026, our third party data processor, Beacon, who provides our supporter database system, informed us of a cyber-security incident affecting their systems.
After discovering the attack, Beacon’s team immediately conducted a thorough investigation with the support of an independent cyber forensics’ expert and law enforcement.
As soon as we were told, we took immediate steps to contain the risk, secure our own systems, and begin an investigation with the processor. We have reported this to the Information Commissioner’s Office (ICO) and the Charity Commission.
Based on our current investigation, the following information relating to you may have been involved:
• Your name and email address
• Postal address and phone number
• Donation history (dates/amounts)
• Date of birth
• Gift Aid information, including confirmation of your UK taxpayer status and any Gift Aid declarations
• Transaction information, including references relating to donations or other payments made to North Yorkshire Hospice Care
• Employment or volunteering information that you have shared with us, such as details of your employer or volunteer role
• Health information that you have voluntarily shared with us for fundraising or supporter purposes. This does not include clinical records or information held within our patient care systems
• Bereavement-related information, including records associated with donations made in memory of a loved one or donations linked to our bereavement services. This does not include client records or any information held within our Just’B’ service.
• Information relating to children and young people (under 18), where they have attended or participated in our events
While we have no evidence that your information has been misused, we recommend remaining vigilant for any unexpected emails, text messages or phone calls claiming to be from us (North Yorkshire Hospice Care or Saint Michael’s Hospice, Herriot Hospice and JustB) or asking for personal or financial information. We will never ask you to provide sensitive information by email, telephone or text message.
• Be cautious of unexpected emails, texts or calls asking for personal details or payments
• Do not click links or open attachments from unknown senders
• Consider updating passwords on any accounts where you reused the same password
• Monitor bank and credit card statements for unusual activity
• If you notice suspicious activity, or suspected identity theft, contact your bank and report it to Action Fraud (www.actionfraud.police.uk).
We take data security seriously. In addition to containing the incident, we have:
• Required the processor to provide a full forensic report and timeline
• Reviewed our contracts and data processing agreements to strengthen security obligations
We understand you may have concerns. You can:
• Read our FAQs below which will be updated via this page.
• Contact our dedicated helplines on 01609 777413 (option 2) or 01423 878628 or email info@saintmichaelshospice.org (Mon–Fri, 9 am to 5 pm)
• If you wish, you can also contact the ICO directly on 0303 123 1113 or via their website.
As we wanted to communicate this news to you as soon as possible, our apologies that this letter is not bespoke to you, but if you have a direct relationship with one of our team members, please feel free to contact them direct if you would like to discuss this through.
Thank you for your continued support. We are committed to keeping your information safe and will provide further updates if our investigation reveals anything new that affects you.
On 3 August 2026, our third-party data processor, Beacon, informed us of a security incident affecting systems they operate on our behalf. As soon as we were told, we took steps to contain the risk, secure our own systems, and begin an investigation with the processor. We have reported this to the Information Commisioner’s Office (ICO) and the Charity Commission.
Based on our current investigation, the following information relating to you may have been involved:
Under UK GDPR, we are the “data controller” and remain responsible for your data, even when it’s processed by a third party on our behalf. When a processor has a breach, they must tell us without undue delay, and we must assess the risk, report to the ICO where required, and inform affected individuals if there is a high risk to their rights and freedoms.
No. Payment card and bank details are held by our separate payment provider and were not stored on the affected system.
At this time, we have no evidence that your information has been misused. However, any breach can increase the risk of phishing emails, scam calls, or identity fraud, so we’re advising supporters to be extra vigilant.
Practical steps you can take now:
Our processor is investigating the root cause. At this stage, we can share that Beacon believe that encrypted copies of their back-up systems were likely downloaded. We will update this FAQ if our investigation reveals anything new that affects you.
We are taking this incident very seriously and are committed to keeping your data safe.
No. Your donation records and Gift Aid declarations remain secure and unchanged. If we need to contact you about any administrative matter, we will do so via official channels only.
We will only contact you about this incident from official email addresses ending in @saintmichaelshospice.org, @herriothh.org.uk, justb.org.uk or @hospice-care.org.
We will not ask you for passwords or payment details by email. If you’re unsure, do not proceed and contact us directly.