
We want to let our supporters and community know about a cyber-security incident involving Beacon, the external company that provides the fundraising customer relationship management system, or CRM, used by Rotherham Hospice. We are sharing this information openly because people trust us with their personal information, and transparency is important to us.
The incident occurred within Beacon, our external fundraising CRM provider, not within Rotherham Hospice’s own IT systems. No clinical records, patient-care information, volunteering records, bank or card details, or passwords were held in Beacon for us.
The incident took place within Beacon’s systems, not within Rotherham Hospice’s own IT network. Beacon has confirmed that an unauthorised third party gained access to its systems. Copies of database backups were made and were likely downloaded. Beacon has said it may not be possible to determine exactly which customer records were involved. Although Beacon stores data in encrypted form, its specialists believe it is possible that the unauthorised party could have decrypted it. We are therefore taking the cautious approach that information held in our Beacon account may have been affected.
What we use Beacon for
Rotherham Hospice uses Beacon only as a fundraising CRM. It helps us manage our relationships with supporters and record fundraising activity.
Beacon is not our clinical database and it is not our volunteering database. If someone is also known to us as a person receiving care, a family member or a volunteer, only any separate fundraising or supporter information held about them in Beacon may potentially be involved, not their clinical or volunteering record.
What information may have been involved
Our review identified 32,102 contact records in Beacon: 27,593 relating to people and 4,509 relating to organisations. This is the maximum number of records potentially involved. It does not mean that every record was accessed or downloaded.
Depending on the record, the information may have included:
- name
- postal address
- email address
- phone number
- donation history
- date of birth, in a limited number of records
- gender, in a limited number of records
Not every record contained every type of information.
What was not held in Beacon
The fundraising records we held in Beacon did not contain:
- bank account details
- debit or credit card details, or other payment credentials
- passwords
- healthcare or clinical records, or details of care
- patient records from any of our care services
- volunteering records from our volunteer database
What is the possible risk?
The most likely risk is that someone could use contact details, or knowledge of a person’s support for the hospice, to make a scam email, text message or telephone call appear more convincing. In a smaller number of records, a date of birth combined with contact details could also increase the risk of identity-related fraud.
At the time of this update, we have no evidence that anyone’s information has been misused. Beacon has also said that its monitoring has found no data linked to this incident online. Because no bank account, card or password information was held in Beacon for us, the incident does not by itself provide access to a person’s bank, card or online accounts
What should I do?
You do not need to contact us or take any immediate action unless you have a specific concern. We recommend that you:
- be cautious about unexpected emails, text messages or calls claiming to be from Rotherham Hospice, Beacon or another organisation
- do not click unexpected links or give anyone your password, full bank or card details, or one-time security codes
- verify any request by contacting us using the details on our official website or by calling 01709 966 000
- contact your bank immediately if you believe you have shared financial information with a scammer or notice suspicious activity
Rotherham Hospice will never ask for your password or a one-time security code in connection with this incident.
What are we doing?
Although the incident happened within Beacon’s systems, Rotherham Hospice remains responsible for responding properly to any risk involving the personal information we hold. We have reported the incident to the Information Commissioner’s Office and are also reporting it to the Charity Commission.
We have taken advice from our outsourced Data Protection Officer and cyber insurer, reviewed the information held in our Beacon account, and are taking steps to inform people whose records may have been held there. We are also reviewing our supplier assurance, data retention, access and security arrangements.
Beacon has told customers that it has contained the incident, remediated the vulnerability, reset relevant credentials, introduced additional security monitoring and has seen no ongoing unauthorised access since containment. We will continue to monitor Beacon’s investigation and will update this page if there is any material change.
Our commitment to you
We know that our supporters place a great deal of trust in Rotherham Hospice. We are very sorry for the concern this incident may cause. Our decision to inform people openly, even though we cannot yet know whether every record was involved, reflects our values and our commitment to transparency, accountability and care.
Questions or concerns
Please contact our Data Protection Officer:
Email: dataprotection@rotherhamhospice.org.uk
Please include “Beacon CRM incident” in the subject line of any email so that we can direct your enquiry quickly.




