
Data Security Incident
Data Security Incident Update
Last updated: 10th August 2026 - 15:15
​
An important update
We are sorry to let you know about a cyber security incident involving Beacon CRM, a trusted third party that we use to securely store some of our supporter and beneficiary information.
​
We understand that this news may be worrying, particularly if you have shared personal or health information with us. We want to be as open and transparent as possible about what has happened, what we know, what we don't yet know, and what we are doing.
​
Please be assured that protecting your personal information is something we take extremely seriously.
What happened?
Beacon has informed us that an unauthorised third party gained access to its systems using compromised credentials.
​
Their forensic investigation has confirmed that copies of database backups were made and that the available evidence indicates they were downloaded by the unauthorised third party. However, at this time, there is some uncertainty about the impact on the data held on Beacon
​
Beacon has advised organisations using its system to assume that all information stored within Beacon, including attached documents and files, may have been downloaded.
​
This incident affected Beacon's systems. Inflammatory Neuropathies UK's own systems have not been impacted.
​
Beacon is continuing to investigate the incident with independent cyber security specialists and is working with the relevant authorities.
What information could be affected?
The information we hold is different for every individual.
​
Depending on your relationship with us, and what you have shared with us, information held within Beacon may include:
-
Your name and contact details
-
Information about your involvement with Inflammatory Neuropathies UK
-
Information about services you have received from us
-
Information about membership
-
Correspondence you have had with us
-
Documents attached to your record
For some people, this may also include special category personal data, such as:
-
Health information, including diagnosis, treatment information, hospital details, condition notes, ventilator status, ability to work and similar information shared with us
-
Ethnicity
-
Religion or belief
-
Sexual orientation
Not everyone will have all of this information stored.
​
Importantly, payment card details, bank account details and other financial payment information are not stored within Beacon and are therefore not affected by this incident.
Why have I received an email?
We have contacted people directly where we believe the information held about them includes special category personal data or other information that could present a higher risk if accessed.
​
We are doing this because we believe it is the right thing to do and because UK data protection law requires organisations to notify individuals where a personal data breach is likely to result in a high risk to their rights and freedoms.
What are we doing?
As soon as we became aware of the incident we:
-
Secured our access to Beacon by changing passwords and resetting connected systems
-
Carried out our own assessment of the risks to individuals
-
Reported the incident to the Information Commissioner's Office (ICO)
-
Began working closely with Beacon to understand the nature and impact of the incident
-
Put arrangements in place to inform individuals potentially impacted when we had the correct information to do so, and to keep people informed as the investigation continues
We will continue to review new information as it becomes available and will provide further updates if anything changes.
What does this mean for you?
At present, we are not aware of any evidence that information from this incident has been published online or misused.
​
However, because Beacon has advised us to assume that information stored within Beacon may have been downloaded, we recommend that everyone remains vigilant.
​
The main potential risks are:
-
Phishing emails or text messages
-
Scam phone calls
-
Attempts to obtain further personal information by pretending to be a trusted organisation
-
Someone learning sensitive information about your health or personal circumstances
What should I do?
As a precaution we recommend that you:
-
Be cautious of unexpected emails, texts or phone calls, particularly if they ask you to confirm personal information or click on links
-
Never share passwords, one time passcodes or security codes following an unexpected request
-
Check email addresses carefully before responding
-
If you reuse passwords across different websites, consider changing those passwords and enable multi factor authentication where available
-
Contact us if you receive any communication claiming to be from Inflammatory Neuropathies UK that causes you concern
Where can I get more advice?
The following organisations provide trusted information:
​
National Cyber Security Centre
Practical advice about phishing, scam emails, suspicious messages and staying safe online.
​
Beacon CRM
Information about the incident and answers to frequently asked questions.
https://www.beaconcrm.org/incident-faqs
​
Information Commissioner's Office
Information about your rights and how personal information should be protected.
How can I contact you?
If you have any questions or would like to discuss the information we hold about you, please contact us.
Email: hello@inflammatoryneuropathies.uk
Telephone: 01529 469910
Our team will do everything we can to help.
​
Need more information?
If you have any questions about this incident, would like to discuss the information we hold about you, or need any support, please contact us. We will do everything we can to help.
​
Data Protection Lead
Email: rich@inflammatoryneuropathies.uk
Telephone: 01529 469910
​
Alternatively, you can contact our team at hello@inflammatoryneuropathies.uk or by calling 01529 469910.
If, after speaking with us, you remain unhappy with how we have handled your personal information, you have the right to raise your concerns with the Information Commissioner's Office (ICO), the UK's independent regulator for data protection.
​
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Telephone: 0303 123 1113
Updates
We will update this page whenever we receive confirmed information from Beacon or there are any significant developments.
​
Update history
10th August 2026 – Initial statement published.
10th August 2026 - FAQs added
Thank you for your patience and understanding.
​
We are genuinely sorry that this incident has occurred. People place enormous trust in us when they share their personal information, and we never take that responsibility lightly. We remain committed to keeping you informed, supporting anyone who has concerns, and continuing to work with Beacon and the relevant authorities as the investigation progresses.
​
Frequently Asked Questions (FAQ): Data Security Incident
1. What happened?
Beacon recently identified a data security incident involving unauthorised access to some of their systems and information, including our CRM (contacts database) which is hosted by them. As soon as they became aware of the issue, they took immediate steps to secure their systems, investigate what happened, and understand any potential impact on members. ​
2. How was the incident discovered?
The issue was identified through Beacon’s security monitoring processes and was immediately investigated. They also engaged specialist IT and cyber security experts to help us understand the incident and take appropriate action.
3. What information may have been affected?
The investigation indicates that some information may have been accessed.
​
The information involved may include:
-
Name
-
Contact details (such as email address, postal address or telephone number)
-
Special category data such as health conditions
-
Information you may have provided when contacting us or using our services
4. Does this mean my personal information has been misused?
There is currently no evidence that any information has been misused as a result of this incident.
However, we are continuing to monitor the situation closely and recommend that everyone remains vigilant for any unexpected emails, phone calls or messages requesting personal information.
5. What is Inflammatory Neuropathies UK doing about it?
Protecting our members' information is extremely important to us. Since discovering the incident, Beacon has:
-
Secured the affected systems
-
Engaged independent cyber security specialists
-
Conducted a thorough investigation
-
Enhanced security measures where necessary
We have
-
Reviewed our policies and procedures
-
Reported the matter to relevant authorities where appropriate
We are committed to learning from this incident and strengthening our safeguards further.
6. Have you reported the incident?
Yes. We have followed our legal and regulatory obligations and have notified the appropriate authorities where required.
​
We are also keeping affected individuals informed as we learn more.
7. What should I do now?
As a precaution, we recommend that you:
-
Be cautious of unexpected emails, texts or phone calls claiming to be from Inflammatory Neuropathies UK or other organisations
-
Never share passwords or sensitive personal information unless you are certain of the recipient's identity
-
Use strong, unique passwords for online accounts
-
Report any suspicious communications to us
These are sensible precautions and do not necessarily mean your information has been misused.
8. How can I tell if a message is genuinely from Inflammatory Neuropathies UK?
Official communications from us will:
-
Come from our recognised email addresses
-
Never ask you to disclose passwords
-
Never ask you to share banking details by email
If you are unsure whether a communication is genuine, please contact us directly using the contact details on our website.
9. Could this affect my medical information?
We understand that many members may be particularly concerned about health-related information.
The investigation is continuing, but we will contact anyone directly if we identify that their specific information may have been affected.
We recognise the sensitive nature of health information and are treating this matter with the utmost seriousness.
10. Will this affect the services and support I receive?
No. Our services and support continue as normal.
​
Our team remains available to provide information, guidance and support, and we are working hard to minimise any disruption.
11. How will I be kept informed?
We will continue to provide updates as appropriate through the website.
We are committed to sharing information promptly and transparently.
12. Who can I contact if I have questions or concerns?
If you have any questions or concerns about this incident, please email us or check our website for further updates:
hello@inflammatoryneuropathies.uk
​
We understand that incidents like this can cause concern, and we are here to answer your questions and provide support.
​
