Update as of 17th August 2026:Â
Beacon has now confirmed the cause of the incident and told us it has been resolved: the vulnerability that allowed access has been closed, the affected credentials have been reset, and enhanced monitoring is now in place around the clock. Beacon has found no ongoing unauthorised access since the incident was contained, and no sign so far that any information has been published or misused. Their investigation is continuing and a final summary is expected in the coming weeks. We’ll keep this page updated. In the meantime, as a sensible precaution, please stay alert to any unexpected emails, calls or messages asking for personal or financial details, and contact us at [email protected] if you have any questions.
Previous updatesÂ
5 August 2026 at 11:45am
There has been a data security incident that may relate to the information we hold. We want to be open about what’s happened, what it means, and what you can do.Â
This incident doesn’t only affect Finding Your Feet, it affects over 1,000 charities across the UK that use the same database provider, Beacon.Â
What happenedÂ
Beacon, the organisation that provides the database we use to manage our records, notified us on 3 August 2026 that an unauthorised third party had compromised their systems. We understand that copies of their database – which includes information we hold about you – were likely made and downloaded. Beacon is still identifying exactly what data may have been affected but note that we do not hold any payment information for you in this system.Â
Beacon’s investigation is ongoing. At this stage there is no evidence that the information has been shared publicly or misused, and no ransom has been demanded. We’ll update this page if anything changes.Â
What information may be involvedÂ
This depends on your relationship with us:Â
- If we support you, it may include your name, address, contact details, DOB, information relating to the support we provide. No bank, card or payment details are held in our system. Â
- If you’re a supporter or donor, it may include details such as your name, address, DOB, contact details, and a record of your support. No bank, card or payment details are held in our system.Â
What we’ve doneÂ
- We took immediate action on 3 August 2026 to secure our account.Â
- We reported the incident to the Information Commissioner’s Office (ICO) on 3 August 2026.Â
- We followed the recommended technical steps, including resetting access and reviewing our connected systems.Â
- We’re contacting those most likely to be affected directly, and making this information available here for everyone.Â
- We’re reviewing all our internal policies and procedures relating to cyber security.Â
NoteÂ
The main risk from an incident like this is phishing – emails, calls or messages designed to look genuine in order to get personal or financial information from you. Occasionally these can be made to look like they come from a charity you know.Â
- We will never ask you for your password or payment details by email or over the phone.Â
- Be cautious of any unexpected contact that references Finding Your Feet, especially anything asking for personal or financial details, or containing suspicious links to click.Â
- If a message seems to be from us but feels off, don’t click any links or reply – contact us directly using the details below.Â
- If you are unsure if the call is from us, you can hang up the phone and call us back on 0141 258 4868.
- For general guidance on staying safe after a data breach, the National Cyber Security Centre has helpful advice at ncsc.gov.uk/guidance/data-breaches. Â
Contact usÂ
If you have any questions or concerns, please email us at [email protected].Â
We’ll keep this page updated as we learn more. Thank you for your understanding, we’re sorry for any concern this may cause. Â