Beacon CRM Security Incident

The MAST service is delivered by a partnership of organisations: Project 6, The Cellar Trust, Hale, and until March 2026, Carers’ Resource. Project 6 is the data controller for the information held about people supported through the service.

Beacon CRM is the database used by the MAST partnership to record information about the support you have received. This may include your name, contact details, date of birth, health status, demographic information such as gender and ethnicity, and details of the interventions or support you have received.

Beacon has informed us that it experienced a security incident involving unauthorised access to its systems, potentially affecting all of its customers. As a result, information held within Beacon CRM may have been accessed. We are continuing to work with Beacon to understand exactly what information relating to the MAST service may have been affected.

We understand that this news may be upsetting, particularly because Beacon CRM can contain sensitive personal information.

At this stage, there is no evidence that any personal data held by Project 6 or the MAST service has been misused or published. However, Beacon has advised that database backups may have been copied by an unauthorised third party, and therefore there is a risk that personal information relating to the service may have been accessed.

As soon as we became aware of the incident, we took steps to assess the potential impact, began gathering information from Beacon, and reported the matter to the Information Commissioner’s Office (ICO) and the Charity Commission.

At present, there is no specific action we are asking you to take, other than to remain vigilant for any emails, messages, links you have been sent or other contact that seems unusual or suspicious.

We recognise that you may have concerns about your personal information and that this incident may affect your trust in how your information is handled. Please be assured that all the MAST partners are treating this matter extremely seriously and are working with Beacon to understand the full extent of the incident and any risks to individuals.

Beacon is publishing updates about the incident on its website, including answers to frequently asked questions and details of its ongoing investigation. You can find the latest information here: Beacon CRM Incident Updates

At the moment, the information available about the details of the breach is limited. However, we are committed to being open and transparent throughout this process. As further information becomes available, and if we identify that any specific action is required from you, we will contact you again as soon as possible.