Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen
People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

Why it matters
What this means for organisations holding critical data
People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.
What happened
George House Trust, a Manchester charity that has supported people living with HIV since 1985, has told service users that their sensitive and personal health information may have been stolen. The charity said the material was downloaded by attackers, although it has not been published and there is no sign so far that it has been misused.
The information held on the targeted database included addresses, email addresses, telephone numbers, and notes and records about each person's engagement with the charity.
The breach did not begin at the charity. It began at Beacon, a technology company whose database system is used by more than a thousand charities across the United Kingdom. Beacon said the incident happened at the end of July and that it immediately engaged external cyber security experts to contain and investigate it. George House Trust was informed on 3 August and told affected people three weeks later, once it had reviewed which records held sensitive data.
Reporting by the BBC indicates the wider incident potentially affects up to 1,500 charities.
Why this one matters more than most
Most breach stories are measured in record counts. This one is measured in consequence. For someone living with HIV, the disclosure of a health status, an address and a set of case notes is not an administrative inconvenience. It is a safety issue, a family issue and, in some circumstances, an employment issue. Special category data under the UK GDPR is treated differently in law precisely because the harm is different in kind.
The charities involved did nothing exotic. They used a sector platform that most small organisations would sensibly choose over building their own. The platform was connected, the records were live, and one intrusion reached across a thousand organisations at once.
The failure mode
A single connected repository serving an entire sector creates a single path to that entire sector's most sensitive records. The supplier can be competent, responsive and well advised, as Beacon appears to have been, and the outcome for the individual is unchanged. Once records are reachable, they are copyable.
Small charities also carry a second exposure. They rarely hold a copy of their own historical case records outside the platform. When the supplier is breached, the charity has neither control over the disclosure nor an independent copy of what it is accountable for.
The Firevault view
A supplier breach should not automatically become your data breach, and it should certainly not become your service users' health disclosure.
Offline Secure Storage® keeps retained records physically disconnected from the platforms, accounts and networks that attackers compromise. Live case management stays online where the work happens. Historical case notes, closed files, safeguarding records and archived correspondence do not need to remain reachable, and once they are held offline there is nothing for an intrusion at a shared supplier to enumerate or export.
The practical question for any charity board this week is narrower than it sounds. Which of the records on your supplier's database still need to be online, and which have simply never been moved off it?
What to do now
Ask your platform supplier which categories of your data were reachable, not only which were confirmed taken. Identify the special category records you hold and the retention periods that actually apply to them. Then remove from the connected estate anything you are keeping for accountability rather than daily use, and hold it offline under your own control.
Mark Fermor, Firevault
How Firevault would handle this
Controls an auditor can physically verify
Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.






