Abseil for CTS - Saturday 12th September

Glide over the Peacehaven Cliffs, embrace fear, and do something BIG for young people facing homelessness.

Data Breach of Donation Platform

The Clock Tower Sanctuary takes its responsibility to protect sensitive personal information very seriously. 

On 3 August 2026, we were informed that Beacon CRM, which processes fundraising and supporter information on our behalf, had experienced a cyber-security incident. Beacon CRM’s current understanding is that compromised user login details were used to gain unauthorised access to its systems. 

What we know so far 

Beacon CRM has established that copies of its database backups were made. Although it has not yet confirmed that data was taken, the evidence currently available suggests that these copies were likely downloaded. This means that personal contact information, held in our Beacon account before 5am on 27 July 2026 may have been accessedThere is no evidence that any card details or bank account information has been compromised. 

Who will this affect?

On Beacon we store information that our donors share with us, this may include names, contact details and address, organisation or employer, correspondence and communication preferences and, where relevant, information about donations, Gift Aid or your wider relationship with us. We are awaiting further updates from Beacon as to the specific substance of the data that has been breached. 

Beacon has said there is currently no evidence that the information has been published online or that a ransom demand has been made. Its investigation is continuing with external cyber-security specialists. You can read more about what Beacon has said about the incident herehttps://www.beaconcrm.org/incident-guidance  

As personal data has been breached, in accordance with the Data Protection Act (2018), we have reported this both to the Information Commissioners Office and to those individuals affected. In the interest of full transparency, we therefore wanted to communicate this widely at the first possible opportunity.

The clearest current risk is that someone could use personal information to make a fraudulent email, telephone call or message appear more convincing. We ask that all of our donors be particularly cautious about unexpected communications referring to the Clock Tower Sanctuary, your donations or your relationship with us. Do not click unexpected links, or provide passwords, security codes, banking information or other personal details. 

What we are doing now 

Our immediate priority has been to notify the supports affected by the breach so that they can take appropriate remedial steps. We have also begun taking further precautionary action, including securing access to our Beacon account, resetting passwords and disconnecting applications and integrations with Beacon. In doing so, we are following guidance from the Information Commissioner’s Office and the Charity Commission and meeting our regulatory reporting requirements.  

You can read our full Privacy Policy on our website here: https://www.thects.org.uk/privacy-policy/

What you can do now 

We know that loss of data can be deeply unsettling, we apologise unreservedly for the concern this incident may cause. We will provide further information to any donors whose information may have been accessed as soon as Beacon’s, or our own, investigation identifies any material changes to the position outlined above. We understand that this may affect trust in us, and if you have a recurring donation you wish to change your preferences on, please do get in touch. 

We will keep this public statement updated as we receive new information.  

If you receive a communication that appears suspicious, please contact us independently on 01273 722 353 (Option 1) or at info@thects.org.uk. Please do not use contact details or links contained within the suspicious message itself. 

 

FAQs 

1. Why does the Clock Tower Sanctuary use a CRM? Why did we choose Beacon? 

It is standard procedure for charities to use a CRM (Customer Relationship Manager) to manage and monitor their communications with and support from the public. This is to keep all of this information in one place securely and ensure consistency. We transitioned to Beacon in 2023 after reviewing five different CRM options. We completed a thorough due diligence of their security measures, in line with our GDPR, Privacy and Data Compliance policies. Beacon are one of the most popular CRM providers for charities and they have confirmed that all of their customers are affected. They are in communication with us and their other customers as the breach unfolds and will continue to update this page as the situation develops.  

 2. What does the Clock Tower Sanctuary do to protect the data it collects? 

The Clock Tower Sanctuary has rigorous policies and procedures in place to protect the data and privacy of our supporters, staff and service users. We have several policies in place covering topics such as GDPR, Data Compliance & Privacy, which are reviewed every two years by our senior management team and Board of Trustees. We are completely committed to maintaining the highest standards and are conducting a full investigation into this breach of a subcontracted organisation. 

 3. Will you continue to use Beacon in the future?  

Our top priority is investigating the breach at Beacon and ensuring anyone affected is informed and protected. Upon completion of the investigation, we will review our future data needs in line with our policies and make a decision about the right donor CRM for the Clock Tower Sanctuary.

*Last updated 05/08/26 at 11:56*