Data security incident at our CRM provider

Last updated: 05/08/2026

Our supporter database provider, Beacon, has told us they experienced a cyber security incident. Some of the information we hold about our supporters may have been copied.

What information was involved

Names and email addresses, and for a small number of people postal addresses and phone numbers. Records of donations, including dates and amounts. No payment card or bank details were held in this system, so none were involved.

What we are doing

We have reported this to the Information Commissioner's Office. We have disconnected and reset the systems that link to our database. We are contacting everyone we hold a valid email address for.

There is currently no evidence that any information has been published or misused, and we are not aware of any fraud or harm resulting from this.

What you can do

A potential risk is that someone could use this information to make a scam email, letter or phone call look more convincing, because they may know that you support us and what you have given.

If you receive something unexpected that appears to come from One-Eighty, or any charity or business, there's always value in acting with caution.

One-Eighty’s emails are usually sent from fundraising@one-eighty.org.uk. If an email appears unusual, do not reply or follow any links. Instead, start a new email to fundraising@one-eighty.org.uk to check whether the message is genuine.

One-Eighty’s official donation page is https://one-eighty.org.uk/donate. For additional security, type this address directly into the browser and check the address bar before making a donation.

Information from Beacon

Beacon have shared this page https://www.beaconcrm.org/incident-faqs primarily aimed at their clients but it may offer useful information.

If you have questions

Please contact Matt or Ruby at fundraising@one-eighty.org.uk. We are sorry this has happened, and we will update this page if anything changes.