Beacon CRM Cyber Security Incident

Category: Uncategorised

Author: Catherine Colwell

August 05th, 2026

The Usual Place (Inspired Community Enterprise Trust Ltd) has been informed that Beacon CRM, our membership and service delivery platform provider, has experienced a cyber-security incident involving unauthorised access to its systems.

Beacon believes that copies of its database backups may have been downloaded.  This means that Usual Place membership information held on the platform, including names, email addresses and other contact details, may have been accessed.

Credit card and payment details have not been compromised and no health, medical or HR information is held on Beacon. 

We have informed the ICO (Information Commissioners Office) and are following SCVO (Scottish Council for Voluntary Organisations) Guidance to Charities.  We are also making staff, volunteers, young people, members, donors etc aware of the incident so that they can remain vigilant. All connected people should be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.

In accordance with Inspired Community Enterprise Trust Ltd (The Usual Place) GDPR data-retention policy, other than the information listed above, we do not store confidential information within Beacon CRM.

Beacon is investigating the incident with external cyber-security specialists and is working with the relevant authorities. The Usual Place will provide further information should this become necessary.

Anyone with questions or concerns should email board@theusualplace.org

Signed

Amy Wright and Elaine Crichton

Co-Chairs
Inspired Community Enterprise Trust Ltd (The Usual Place)