06 Aug Cyber-Security Incident – July 2026
Last updated: 6 August 2026
Prison Fellowship Northern Ireland uses Beacon, an external customer relationship management (CRM) system, to manage information about our supporters and volunteers.
Beacon notified us on Monday 3rd August at 13:22 GMT of a cyber-security incident involving unauthorised access to its systems on Monday 27th July 2026 at 04:00 GMT. As a result, some personal information held by PFNI may have been affected.
We understand this may be concerning. This page explains what we currently know, what we are doing in response and the steps you can take to help protect yourself.
What happened?
Beacon has told us that compromised login credentials were used to gain unauthorised access to its systems. Copies of database backups were made and, based on the evidence currently available, those copies were likely downloaded.
This means that some personal information held by Prison Fellowship Northern Ireland in Beacon may have been accessed. Beacon’s investigation is continuing, and the full scope of the incident has not yet been confirmed.
We are not currently aware of any misuse of personal information connected with this incident.
What information may be involved?
The information potentially affected may include contact details and other information held in our supporter records, such as:
- Name
- Postal address
- Email address
- Telephone number
- Donation and Gift Aid information
- Communication preferences
- Other information provided to us in connection with your relationship with PFNI
The exact information involved will depend on the records held for each individual. Credit/debit card details and bank details are stored in separate systems and are not affected by this breach. If you are at all concerned, please email us at info@pfni.org.
What are we doing?
Prison Fellowship is:
- Working with Beacon to understand exactly what happened and what information may have been affected.
- Assessing the possible risks to the people whose information we hold.
- Reviewing our access arrangements, integrations and security credentials.
- Taking appropriate steps to protect our systems and information.
- Notifying the Information Commissioner’s Office (ICO).
- Notifying the Charity Commission for Northern Ireland.
Beacon has told us that it has taken immediate steps to secure its systems and prevent further unauthorised access. It is also conducting a forensic investigation with external cyber-security specialists and monitoring for evidence that information connected with the incident has been published or misused.
We will update this page if we receive significant new information that changes our current assessment.
What you can do
Please remain alert to unexpected emails, telephone calls, text messages or social-media messages that appear to come from PFNI or refer to your relationship with us.
In particular:
- Be cautious about unexpected requests for money, passwords, banking details or security codes.
- Do not open unexpected attachments or click suspicious links.
- Do not provide personal or financial information in response to an unsolicited message.
- Check any request by contacting us directly.
- Do not use telephone numbers, email addresses or links supplied in a suspicious message.
We will never ask you to provide passwords or security codes by email. If you receive a suspicious communication that appears to relate to Prison Fellowship, please contact us.
Further information and contact
We are sorry for the concern this incident may cause. We appreciate your patience while Beacon’s investigation and our own assessment continue.
If you have questions or need assistance, please email info@pfni.org
Thank you for your understanding and prayerful support.
Robin Scott
Prison Fellowship Northern Ireland