Skip to page content

Data Breach 3/08/2026

We want to let you know about a data security incident affecting a third-party company that we use to manage the data of supporters, past and present. The company is called Beacon CRM and they manage the data of over 1,500 charities and organisations nationwide, including Cheltenham and Gloucester Hospitals Charity.

At this time, we are not aware of any misuse of personal information. However, we wanted to inform you of this incident so that you can be vigilant about any possible future misuse.

It is important to note that Beacon CRM is not a financial system and no bank, Direct Debit or card details were stored with your supporter record.

What happened?

On Monday 3 August 2026, Beacon CRM informed us that it had experienced a cyber security incident involving unauthorised access to its systems. Beacon CRM has engaged specialist cyber security experts and is continuing to investigate the incident. It is working with law enforcement and the relevant regulators.

At this point we must assume that all the data they hold, for all their clients, including ourselves, is affected.

What information may be involved?

The information we store within our Beacon CRM system may include some or all of the following:

  • Name
  • Postal address
  • Email address
  • Phone number (in some cases)
  • Donation history: The date and value of donations or payments
  • Gift Aid status
  • Correspondence e.g. thank you letters or messages you have left with us

Have my medical records has been affected?

No. We are the charity for Gloucestershire Hospitals NHS Foundation Trust, but we are a separate organisation and we do not hold patient records. No medical or clinical information was held in the affected system. The information we hold relates to your support for the charity.

What we are doing

Since being notified of the incident, we have:

  • Completed a security checklist provided by Beacon CRM to update all passwords and links
  • Reviewed the information that may have been affected
  • Assessed the potential risks to the individuals whose information we hold
  • Considered our legal obligations under data protection law
  • Reported the breach to the Information Commissioner's Office (ICO)
  • Continued to monitor developments as Beacon's investigation progresses

What should you do?

We are not currently aware of any misuse of your personal information as a result of this incident. However, as a precaution, we recommend that you:

  • Remain vigilant for suspicious emails, correspondence or calls claiming to be from our charity
  • Exercise caution before clicking on links or opening attachments from any unexpected communications
  • Never disclose passwords, verification codes or financial information in response to unsolicited requests
  • Monitor your bank statements: Regularly check your accounts for any unexpected or unauthorised Direct Debits.

Where can I get more information?

We appreciate that this news will be concerning and we are very sorry for any worry it causes.

As any new information comes to light, we will update our website or contact supporters, as appropriate.

If you have any questions please email ghn-tr.fundraising@nhs.net

Thank you for your support.

Yours sincerely,

Charles Homer

Head of Fundraising and Income Generation

Making hospital life better

Every donation you choose to give helps your local hospitals do more to care for you, everyone you love and our passionate NHS staff.
A nurse and Health Care Assistant (HCA) smiling