Data security incident at Beacon, our database provider
We are writing to let you know about a data security incident affecting Beacon, the database provider the Naz and Matt Foundation uses to manage our supporter, donation and fundraising records.
We are sorry to be sharing this news, and we want to be straightforward with you about what has happened and what it means.
What happened
Beacon told us on 3 August 2026 that an unauthorised party had used a stolen access key to get into their systems on 29 July, and that copies of their database backups were taken. Their investigation suggests those copies were likely downloaded.
This was not an attack on the Naz and Matt Foundation. Beacon provides software to more than 1,000 UK charities and we understand that all of them are affected.
What information was involved
Beacon has advised all its customers to assume that everything stored in the platform was taken. For us, that means the information we hold about people as supporters: names, contact details, and where relevant donation and event history.
For a smaller number of people, around 345 out of 2,032, our records also held some identity information such as gender identity, sexuality, religion, ethnic group or accessibility needs. People shared this with us voluntarily so that we could tailor what we offer them. We are contacting everyone in that group separately and individually.
What was not involved
Nothing relating to our support service was in this system. Case notes, casework records and everything connected to the people we support are held in entirely separate, ring fenced systems, specifically so that they are protected. There is no link or transfer between the two. If you have come to us for support, your support records were not affected.
Your payment details were not involved either. Card payments are handled by a separate provider and card numbers are never stored in the database that was affected.
What we know and do not know
At the time of writing there is no evidence that this data has been published or shared online, and no ransom demand has been made. We want to be honest that Beacon may never be able to confirm exactly what was taken, so we are telling you the current position rather than making a promise. If that changes, we will update this page.
What we are doing
We changed our login details straight away as a precaution, although our credentials were not the cause of this, and we replaced all the keys connecting Beacon to our other systems. We have always used two factor authentication on our accounts.
We have reported the incident to the Information Commissioner’s Office, to Report Fraud, and to the Charity Commission. We are reviewing what information we hold, why we hold it, and where it is kept, and we are strengthening how we check the suppliers who hold data for us.
What you can do
There is no immediate action you need to take, but it is worth being a little more careful than usual for a while.
Be cautious about unexpected emails, texts or calls that mention the Foundation or your support for us. We will never ask you for your bank details, passwords or verification codes. Our emails always come from addresses ending in nazandmattfoundation.org. If something looks off, please do not click any links. Come to us directly instead.
If you have questions
Please email us at [email protected]. We would much rather hear from you than have you worry on your own.
You also have the right to raise a concern with the Information Commissioner’s Office at ico.org.uk.
A word about why this matters to us
We know that for many of the people connected to this Foundation, a link to us is not a neutral piece of information. Some of you support us because of your own experience, or because of someone you love. We do not take that lightly, and we are sorry that information about your connection to us has been caught up in this.
Thank you for standing with us.
