Our statement and information for supporters
On Monday 3 August, Molly Rose Foundation was unfortunately informed about a data breach affecting Beacon, the third-party system that we use to manage our donors’ and supporters’ information.
This data breach affects our supporters, donors and service users. We understand that this will be worrying to those affected, and we are truly sorry that this has happened. Protecting your personal information is extremely important to us.
We don’t yet have a full picture of the extent of the data breach, but we are working hard with Beacon to establish the facts as quickly as possible. We will be in touch with everyone affected with more information as soon as we have it.
In the meantime, if you are concerned or have any questions, please get in touch at:dataprotection@mollyrosefoundation.org.
What happened?
On Wednesday 29th July 2026, Beacon, our CRM software provider, became aware that they may have experienced a cyber-security incident. They immediately engaged external cyber-security experts to help investigate and secure their systems. Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of database backups were made.
Molly Rose Foundation was informed by Beacon about the incident on Monday 3rd August.
What information may be involved?
We are continuing to work with Beacon to establish precisely what information may have been accessed and whether any specific individuals face a heightened risk as a result. At this stage, investigations remain ongoing. However, the information stored within our Beacon system may include some, or all, of the following:
- Name
- Address
- Contact details (email address and phone number)
- Gender
- Date of birth
- Record of donations or payments made to Molly Rose Foundation
- Information you have provided to us in connection with our services and activities
What are we doing to address the breach?
Protecting your personal information is extremely important to us. We are continuing to work with Beacon to establish exactly what information may have been accessed. Since being notified of the incident, we have:
- Reviewed the information that may have been affected;
- Assessed the potential risks and taken immediate steps to prevent further unauthorised access;
- Considered our legal obligations under data protection law, including notifying the Information Commissioner’s Office (ICO) and Charity Commission; and
- Continued to monitor developments as Beacon’s investigation progresses;
What should you do?
We are not currently aware of any misuse of your personal information. However, as a precaution, we recommend that you:
- Remain vigilant for suspicious emails, telephone calls, texts or correspondence claiming to be from Molly Rose Foundation or any trusted third party.
- Exercise caution before clicking on links or opening attachments from unexpected communications.
- Never disclose passwords, verification codes or financial information in response to unsolicited requests.
What happens next?
We are committed to keeping you informed. If our investigation identifies any further information that may affect you, we will provide an update as soon as possible. In the meantime, if you have any questions or concerns, please don’t hesitate to contactdataprotection@mollyrosefoundation.org.
We are incredibly grateful for your trust in Molly Rose Foundation and your ongoing support for our cause. We never take your support for granted and I want to sincerely apologise for any worry or concern this incident may cause.
