“We are writing to let you know about a cyber security incident affecting Beacon CRM, the system Yellow Door uses to store information about supporters and donors.
On 3 August 2026, Beacon informed us that an unauthorised person had gained access to its systems using compromised credentials. According to Beacon, copies of database backups were created and may have been downloaded. Their investigation is ongoing, and they have not yet confirmed exactly which records were accessed.
At this stage, we have no evidence that any information relating to Yellow Door supporters has been published, shared or misused. However, because some of the information held within Beacon may have been affected, we wanted to contact you directly and be transparent about the situation.
Information that may potentially have been affected includes:
- Name and contact details such as email address, telephone number or postal address.
- Donation history and Gift Aid records.
- Communication preferences.
- Notes relating to our interactions with you as a supporter or donor.
We understand that privacy and confidentiality are especially important to many people connected with Yellow Door. Some supporters and members of our community may have personal experiences of abuse or may know someone who has accessed support. We appreciate that this news may be unsettling. At present, there is no evidence of misuse of data linked to this incident, and we are working closely with Beacon to understand the scope of the breach and any potential impact.
Importantly, Yellow Door does not store bank account numbers, sort codes, full payment card numbers or card security details within Beacon, and there is currently no indication that financial account credentials have been affected.
As a precaution, we recommend that you:
- Be cautious of unexpected emails, telephone calls, texts or messages claiming to be from Yellow Door, Beacon or another organisation you support.
- Do not provide passwords, bank details, security codes or other sensitiveinformation in response to an unexpected request.
- Check email sender addresses carefully before clicking links or opening attachments.
- Monitor your accounts for any unusual activity and report suspected fraud to your bank or relevant authorities.
- Change the password of your email account.
Please be assured that Yellow Door will never contact you unexpectedly to ask for your password, full payment card details or online banking security codes.
We understand that this news may be concerning and we are very sorry for any worry this may cause. We take the security of personal information extremely seriously and are reviewing the information we hold, our data retention practices, and the additional updates we receive from Beacon as their investigation continues.
If you have any questions or concerns, please contact us at supportus@yellowdoor.org.uk If you are feeling worried or distressed about this incident and need support outside of our office hours, you can contact the Rape Crisis 24/7 Support Line 0808 500 2222, which provides confidential emotional support and information at any time of day or night.
If you would like to make a complaint, please email dpo@yellowdoor.org.uk and here is a link to Yellow Door Complaints Policy.
Thank you for your understanding and for your continued support of Yellow Door.
Kind regards,