We want to let our supporters know about a cyber security incident involving Beacon, the Customer Relationship Management system we use.
If you need an Easy Read version of this information, you can access it on this link.
What happened?
DanceSyndrome uses Beacon for storing data about the people that we work with. This includes people who have taken part in our dance activities, attended our events, made a donation or requested information from us.
Unfortunately, we were contacted by Beacon on Monday 3rd August 2026 about a cyber security breach which has impacted all of the charities that they work with.
The details they provided are as follows:
“On Wednesday 29th July 2026, Beacon became aware that they may have experienced a cyber-security incident. They immediately engaged external cyber-security experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of our database backups were made. We were notified by Beacon that they discovered this incident on Monday 3rd August.”
Within 72 hours of learning about the breach, DanceSyndrome attempted to contact everyone whose data was stored on our Beacon account, in line with GDPR legislation and guidance from the Information Commissioners Office. Some of those emails may have been lost in junk folders or rejected by some email providers, so we are publishing further information here.
Data Involved
DanceSyndrome only collects and stores data that is necessary for our work and that we have a lawful basis to process. Our contacts might have provided us with data via paper or online forms.
We store personal contact information such as home address, phone number, email address and date of birth. We might also store the details of emergency contacts or carers, if those have been provided to us. In some situations, people may have given us information about a disability, neuro-divergence or health issue, this was also stored on Beacon.
Sensitive data such as ethnicity, sexuality, gender, bank details, financial/payment information or passwords/login details have NOT been stored on Beacon by DanceSyndrome, so these should not be impacted by this incident.
This data reach does not relate to information provided on our surveys, questionnaires or our Equality & Diversity Monitoring Form.
The Risks to You
Beacon has provided us with the following information relating to potential risk:
“Whilst the copying or sharing of this data hasn’t yet been confirmed, the evidence Beacon has so far suggested these copies were likely downloaded. There is currently no evidence that this data has been shared on the dark web and there has been no ransom request.”
We are sharing this information now so that you understand what has happened and can take sensible precautions. Being aware that your data may have been involved can help you stay alert to potential scams, phishing attempts and other common risks.
The Take Five to Stop Fraud campaign offers easy read guidance on how to avoid scams and stay safe. It might be useful for you to read. You can read about it on this link.
DanceSyndrome will remain in close contact with Beacon and will update this page if we receive new information about the level of risk or any action you may need to take.
DanceSyndrome’s Actions
DanceSyndrome acted immediately to help mitigate the impact of this breach. Staff members have changed their Beacon passwords, and we have disconnected any applications that can access data in Beacon, in line with Beacon’s recommendations.
We have reported the breach to both the Information Commissioner’s Office and Charity Commission, acting in line with DanceSyndrome’s Data Protection Policy.
This incident relates to Beacon’s systems. We had been assured by Beacon that our data was stored safely and securely, and that it was encrypted for added protection. We have been in communication with Beacon to express our concerns that this breach has occurred.
We want to respond as best we can to protect the people who might be impacted by this breach, and we assure you that we are remaining in contact with Beacon to ensure the best possible outcomes from this unfortunate situation.
Beacon has shared this list of Frequently Asked Questions about the incident, which may be of use to you: https://www.beaconcrm.org/incident-faqs or you can contact them directly at incident@beaconcrm.org.
We understand that this data breach may be upsetting, and we want to reassure you that we are responding carefully, lawfully and in line with our organisational values.
If you need support with understanding this information, please use the Contact Us page to do this.
Many thanks for your understanding.