Air Cadet Charity News

Beacon cyber security incident

Last updated: 14 September 2026

On Monday 3 August 2026, we were notified that Beacon CRM, a database system used by the Air Cadet Charity and over 1,000 other UK charities, had experienced a cyber security incident.

Since our original update, Beacon has completed its investigation with support from independent cyber security specialists and has published its final report.

Update: Beacon investigation concluded

Beacon's investigation concluded that an unauthorised third party gained access to its systems on 27 July 2026 using stolen access credentials.

The evidence suggests the individual may have exported a copy of the entire customer database, which means personal data held within Beacon for the Air Cadet Charity could have been accessed.

Beacon has confirmed that:

  • There is no evidence that payment processor data was compromised.
  • There is no evidence that the Air Cadet Charity was specifically targeted.
  • Independent dark web monitoring has found no evidence that stolen data has been published, sold or shared online.
  • No further unauthorised access has been detected since the incident was contained.
Actions taken by Beacon

Beacon engaged independent cyber security experts immediately after discovering the incident.

The company has since:

  • Fixed the vulnerability believed to have enabled the attack.
  • Reset and replaced credentials that could have been affected.
  • Required all users to reset passwords and re-register two-factor authentication.
  • Commissioned an independent review of its response and remediation work.

An independent assessment conducted by CYFOR Secure concluded that Beacon correctly identified the cause of the incident, removed the unauthorised access and addressed the underlying vulnerability. The assessment also concluded that Beacon's systems are now in a stronger security position than before the incident.

Beacon has introduced a number of additional security measures, including:

  • Enhanced code and deployment security checks.
  • Automated scanning for exposed credentials.
  • More frequent penetration testing.
  • Continuous security testing.
  • Annual independent cyber security assessments.
  • Further investment in security leadership and governance.
The Air Cadet Charity's position

We recognise that this incident has caused concern and appreciate the patience and understanding shown by applicants, recipients and stakeholders while the investigation was completed.

We remain in close contact with Beacon and have reviewed the findings of its final report. Based on the information currently available, there is no evidence of any ongoing unauthorised access or ongoing risk arising from the incident, and Beacon's independent reviewers have confirmed that the vulnerability has been addressed.

At this time, we are not aware of any evidence that data relating to our applicants has been misused. However, we continue to encourage anyone who may be affected to remain vigilant for suspicious emails, phone calls or messages, and to report any concerns immediately.

What should I do?

As a precaution, we recommend that anyone who may have submitted information to the Air Cadet Charity through a grant or bursary application remains vigilant:

  • Be cautious of unexpected or suspicious emails, text messages or phone calls.
  • Never share personal or banking information unless you have verified the identity of the requester.
  • Review online safety guidance from the National Cyber Security Centre.
Questions or concerns?

If you have any questions about this incident, please contact us at dataincident@aircadetcharity.org.uk.

‍

This page was originally published on 5 August 2026 and has been updated following Beacon's completed investigation and publication of its final report.