Beacon cyber security incident
Page updated: 3pm on Friday 7th August 2026
Page updated: 3pm on Friday 7th August 2026
We would like to let you know about a cyber security incident involving an external company called Beacon, which stores fundraising and supporter information on behalf of Blythe House Hospice.
Beacon recently experienced a cyber security incident, and they have confirmed that copies of database backups were likely downloaded by an unauthorised third party. This happened within Beacon’s system and not within the Blythe House Hospice network.
Beacon are unable to tell us what records have been taken or whether they are still encrypted, so there is a possibility that your information is not involved in this incident. However, we have made the decision that you have trusted us with that information, and we would prefer to be open and transparent about the potential that it has been downloaded.
We normally record your name, postal address, email, telephone number, donation and communications history. In some cases, we have recorded date of birth and gender.
The information we keep does vary so not every record will contain all that information.
Importantly, we do not record any financial information such as card details, bank account details, or passwords.
Healthcare and volunteering records are not kept on Beacon so there is no risk to them from this incident.
At present there remains no evidence that Blythe House Hospice supporter information has been misused.
As soon as we were notified, we reviewed our own systems, reset all connections and passwords for Beacon and confirmed that our internal security measures remain in place. We have also notified the Information Commissioner’s Office (ICO) and the NHS Data Protection team.
We have reviewed the information we hold in Beacon, and continue to monitor Beacon’s investigation so that if any further information becomes available or recommendations are made, we can act upon them.
At present, we have no evidence that your information has been published or misused. However, we recommend remaining cautious of any unexpected emails, phone calls or messages that appear to come from Blythe House Hospice or another organisation you know. Please always verify the sender before clicking on links, opening attachments or sharing personal information.
We sincerely apologise for any concern this may cause. Protecting your personal information is extremely important to us, and we wanted to be open with you about this incident and the steps we are taking.
You can also read information from Beacon on their website.
If you have any questions or concerns, please do not hesitate to contact us at: dpo@blythehouse.co.uk or call: 01298 815 388.
Thank you for your support and understanding.