top of page

BEACON DATa BREACH

Cyber Security Incident – July 2026

 

One Mission Society UK uses Beacon, an external customer relationship management (CRM) system, to manage information about our supporters and volunteers.

 

Beacon notified us on Monday 3rd August at 13:22 GMT of a cyber-security incident involving unauthorised access to its systems on Monday 27th July 2026 at 04:00 GMT. As a result, some personal information held by OMS UK may have been affected.

 

We understand this may be concerning. This page explains what we currently know, what we are doing in response and the steps you can take to help protect yourself.

 

What happened?

 

Beacon has told us that compromised login credentials were used to gain unauthorised access to its systems. Copies of database backups were made and, based on the evidence currently available, those copies were likely downloaded.

 

This means that some personal information held by OMS UK in Beacon may have been accessed. Beacon’s investigation is continuing, and the full scope of the incident has not yet been confirmed.

 

We are not currently aware of any misuse of personal information connected with this incident.

 

What information may be involved?

 

The information potentially affected may include contact details and other information held in our supporter records, such as:

  • Name

  • Postal address

  • Email address

  • Telephone number

  • Donation and Gift Aid information

  • Communication preferences

  • Other information provided to us in connection with your relationship with OMS UK.

 

The exact information involved will depend on the records held for each individual. Credit/debit card details and bank details are stored in separate systems and are not affected by this breach. If you are at all concerned, please email us at info@onemissionsociety.org.uk

 

What are we doing?

OMS UK is:

  • Working with Beacon to understand exactly what happened and what information may have been affected.

  • Assessing the possible risks to the people whose information we hold.

  • Reviewing our access arrangements, integrations and security credentials.

  • Taking appropriate steps to protect our systems and information.

  • Notifying the Information Commissioner’s Office (ICO).

  • Notifying the Charity Regulator (OSCR).

 

Beacon has told us that it has taken immediate steps to secure its systems and prevent further unauthorised access. It is also conducting a forensic investigation with external cyber-security specialists and monitoring for evidence that information connected with the incident has been published or misused.

 

We will update this page if we receive significant new information that changes our current assessment.

 

What you can do

 

Please remain alert to unexpected emails, telephone calls, text messages or social-media messages that appear to come from OMS UK or refer to your relationship with us.

 

In particular:

  • Be cautious about unexpected requests for money, passwords, banking details or security codes.

  • Do not open unexpected attachments or click suspicious links.

  • Do not provide personal or financial information in response to an unsolicited message.

  • Check any request by contacting us directly.

  • Do not use telephone numbers, email addresses or links supplied in a suspicious message.

 

We will never ask you to provide passwords or security codes by email. If you receive a suspicious communication that appears to relate to OMS UK, please contact us.

 

Further information and contact

 

We are sorry for the concern this incident may cause. We appreciate your patience while Beacon’s investigation and our own assessment continue.

 

If you have questions or need assistance, please email info@onemissionsociety.org.uk

 

Thank you for your understanding and prayerful support.

 

Melvin Kelly
OMS UK

Our History

Find out more about the story of One Mission, and how we have served God across the world...

Our Partners

Find out more about who is part of OMS UK and the ministries that we are involved in...

bottom of page