3rd August 2026
BART has been informed that Beacon CRM our customer, supplier and volunteer management platform provider, has experienced a cyber-security incident involving unauthorised access to its systems. Beacon CRM is used to securely manage our contacts and communications.
Following advice from the Information Commissioner’s Office (ICO), we are notifying individuals whose personal information may have been affected.
What happened?
Beacon recently informed us that it experienced a cyber security incident in which an unauthorised third party gained access to its systems. Beacon has advised that copies of customer database backups were likely downloaded during the incident. While Beacon’s forensic investigation is continuing, they have advised customers to assume that data held within their Beacon account may have been affected.
What information was involved?
Based on our records, the information that may have been affected includes:
- Name
- Email address
- Telephone number (where held)
- Other contact information provided to BART
Financial information, payment card details, bank account information or medical information relating has NOT been compromised, as BART does not store this information within Beacon CRM.
What are the risks?
At present, we have no evidence that personal information has been misused or published. However, because contact information may have been accessed, there is an increased risk of phishing emails, scam messages or other attempts by criminals to impersonate trusted organisations.
We recommend those affected to:
- Remain vigilant for unexpected emails, telephone calls or text messages.
- Do not click on links or open attachments unless confident they are genuine.
- Be cautious if anyone requests personal or financial information while claiming to represent BART or another organisation.
- Report any suspicious communications to the organisation they claim to represent.
What has BART done?
As soon as we became aware of the incident we:
- Activated our Cyber Incident Response Plan.
- Undertook a formal data breach risk assessment.
- Reported the incident to the Information Commissioner’s Office and Charity Commission in line with our legal obligations.
- Contacted Beacon to obtain further information about the incident and the data affected.
- Continue to monitor updates from Beacon as its forensic investigation progresses.
Beacon has engaged independent cyber security specialists, is working with law enforcement and relevant regulators, and continues to monitor for any evidence that customer data has been misused.
Where can I find out more?
Beacon has published information about the incident, including answers to frequently asked questions and guidance for customers, on its website. https://www.beaconcrm.org/incident-guidance
If we receive any further information from Beacon that changes our understanding of this incident or requires any additional action, we will let those affected know promptly.
If you have any questions or concerns, please contact us using our usual contact details or by emailing info@bristolavonriverstrust.org.
We sincerely apologise for any concern this incident may cause. Protecting the personal information entrusted to us is extremely important, and we are committed to being open and transparent while continuing to work closely with Beacon throughout its investigation.
Thank you for your understanding and your continued support.
Simon Hunter
Chief Executive Officer
Bristol Avon Rivers Trust






