Last updated Wednesday 5 August 2026 at 6.30pm.
On Monday 3 August 2026, we were notified that Beacon CRM, a database system used by the Air Cadet Charity and over 1,000 other UK charities, was targeted in a cyber security incident. We acted immediately to respond and want to reassure our grant applicants and recipients regarding the measures being taken.
What happened?
Beacon CRM became aware of a cybersecurity incident on 29 July 2026 and immediately engaged external cybersecurity experts to secure their systems and investigate the breach. Beacon informed us that compromised credentials were used to gain unauthorised access to their systems, allowing copies of database backups to be accessed. Current evidence indicates that copies of database backups may have been downloaded by an unauthorised third party. Beacon's investigation remains ongoing. Beacon notified affected charities on Monday 3 August 2026.
What information was accessed?
The data held by the Air Cadet Charity within Beacon CRM may include:
- Names and RAFAC email addresses.
- Associated Squadron, Wing or Region bank details.
- In some cases, personal email addresses and home addresses.
- In a small number of cases, personal bank account details.
I am a member of the RAF Air Cadets (RAFAC) (or know someone who is). Am I affected?
Only individuals who have directly submitted a grant or bursary application to the Air Cadet Charity are affected. Because we operate independently from RAFAC, we do not hold personal details for any members other than the information explicitly submitted during a grant application.
What should I do right now?
Where our assessment identifies a higher potential risk to individuals, we will contact those affected directly.
However, we recommend all applicants remain vigilant:
- Be cautious of unexpected or suspicious emails, text messages, or phone calls.
- Never share personal or banking details unless you have verified the identity of the requester.
- Review guidance on staying safe online from the National Cyber Security Centre (NCSC).
What has the Air Cadet Charity done to respond?
Air Cadet Charity takes data privacy and security seriously and maintains a range of security measures to protect the information we hold.
Upon being notified of the incident on Monday 3 August, we immediately:
- Reviewed the initial technical findings provided by Beacon CRM.
- Assessed the nature and extent of the potential impact on our applicants.
- Continued to monitor updates from Beacon regarding their investigation.
- Formally reported the incident to the Information Commissioner’s Office (ICO) in accordance with UK data protection legislation.
We will continue to closely monitor the situation alongside Beacon and the ICO, taking any further protective steps necessary.
.png)
.png)


.png)
.png)