---
title: "Beacon breach: 1,500 charities exposed and an H… | Firevault"
description: "People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026#webpage",
      "url": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026",
      "name": "Beacon breach: 1,500 charities exposed and an H…",
      "description": "People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen",
          "item": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen",
      "description": "People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.",
      "url": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-26T14:28:22.806015+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Insight",
      "wordCount": 582,
      "keywords": "Beacon, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened George House Trust, a Manchester charity that has supported people living with HIV since 1985, has told service users that their sensitive and personal health information may have been stolen. The charity said the material was downloaded by attackers, although it has not been published and there is no sign so far that it has been misused. The information held on the targeted datab",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What happenedWhy this one matters more than mostThe failure modeThe Firevault viewWhat to do nowMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Insight · 26 August 2026 

# Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fbeacon-charity-database-breach-hiv-charity-health-data-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fbeacon-charity-database-breach-hiv-charity-health-data-2026&text=Beacon%20breach%3A%201%2C500%20charities%20exposed%20and%20an%20HIV%20charity's%20health%20data%20stolen%0A%0APeople%20supported%20by%20a%20Manchester%20HIV%20charity%20have%20been%20told%20sensitive%20health%20information%20may%20have%20been%20stolen%20after%20a%20breach%20at%20Beacon%2C%20the%20shared%20database%20platform%20used%20by%20more%20than%20a%20thousand%20UK%20charities.%20One%20supplier%2C%20one%20connected%20database%2C%20national%20exposure.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fbeacon-charity-database-breach-hiv-charity-health-data-2026)[](mailto:?subject=Beacon%20breach%3A%201%2C500%20charities%20exposed%20and%20an%20HIV%20charity's%20health%20data%20stolen&body=People%20supported%20by%20a%20Manchester%20HIV%20charity%20have%20been%20told%20sensitive%20health%20information%20may%20have%20been%20stolen%20after%20a%20breach%20at%20Beacon%2C%20the%20shared%20database%20platform%20used%20by%20more%20than%20a%20thousand%20UK%20charities.%20One%20supplier%2C%20one%20connected%20database%2C%20national%20exposure.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fbeacon-charity-database-breach-hiv-charity-health-data-2026)

![Illustration of a shared charity database platform with one broken connection and confidential health records escaping](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Illustration of a shared charity database platform with one broken connection and confidential health records escaping

Why it matters

## What this means for organisations holding critical data

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [Why this one matters more than most](#section-1)
3.  03 [The failure mode](#section-2)
4.  04 [The Firevault view](#section-3)

**On this page**[What happened](#section-0)[Why this one matters more than most](#section-1)[The failure mode](#section-2)[The Firevault view](#section-3)

## What happened

George House Trust, a Manchester charity that has supported people living with HIV since 1985, has told service users that their sensitive and personal health information may have been stolen. The charity said the material was downloaded by attackers, although it has not been published and there is no sign so far that it has been misused.

The information held on the targeted database included addresses, email addresses, telephone numbers, and notes and records about each person's engagement with the charity.

The breach did not begin at the charity. It began at Beacon, a technology company whose database system is used by more than a thousand charities across the United Kingdom. Beacon said the incident happened at the end of July and that it immediately engaged external cyber security experts to contain and investigate it. George House Trust was informed on 3 August and told affected people three weeks later, once it had reviewed which records held sensitive data.

Reporting by the BBC indicates the wider incident potentially affects up to 1,500 charities.

## Why this one matters more than most

Most breach stories are measured in record counts. This one is measured in consequence. For someone living with HIV, the disclosure of a health status, an address and a set of case notes is not an administrative inconvenience. It is a safety issue, a family issue and, in some circumstances, an employment issue. Special category data under the UK GDPR is treated differently in law precisely because the harm is different in kind.

The charities involved did nothing exotic. They used a sector platform that most small organisations would sensibly choose over building their own. The platform was connected, the records were live, and one intrusion reached across a thousand organisations at once.

## The failure mode

A single connected repository serving an entire sector creates a single path to that entire sector's most sensitive records. The supplier can be competent, responsive and well advised, as Beacon appears to have been, and the outcome for the individual is unchanged. Once records are reachable, they are copyable.

Small charities also carry a second exposure. They rarely hold a copy of their own historical case records outside the platform. When the supplier is breached, the charity has neither control over the disclosure nor an independent copy of what it is accountable for.

## The Firevault view

A supplier breach should not automatically become your [data breach](/learn/breaches), and it should certainly not become your service users' health disclosure.

[Offline Secure Storage](/offline-secure-storage)® keeps retained records physically disconnected from the platforms, accounts and networks that attackers compromise. Live case management stays online where the work happens. Historical case notes, closed files, safeguarding records and archived correspondence do not need to remain reachable, and once they are held offline there is nothing for an intrusion at a shared supplier to enumerate or export.

The practical question for any charity board this week is narrower than it sounds. Which of the records on your supplier's database still need to be online, and which have simply never been moved off it?

## What to do now

Ask your platform supplier which categories of your data were reachable, not only which were confirmed taken. Identify the special category records you hold and the retention periods that actually apply to them. Then remove from the connected estate anything you are keeping for accountability rather than daily use, and hold it offline under your own control.

Mark Fermor, Firevault

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)[

![French tax authority breach exposes 678,000 taxpayers and the land registry behind them](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/french-tax-authority-dgfip-data-breach-2026.jpg)

Insight 

### French tax authority breach exposes 678,000 taxpayers and the land registry behind them

France's Directorate General of Public Finances has confirmed that attackers used compromised access points to extract tax and cadastral data on 678,000 individuals and businesses. The same seller claims to have held a live session on the central land registry platform covering roughly 20 million people.

17 Aug 2026 3 min 







](/news/french-tax-authority-dgfip-data-breach-678000-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)