We want to let you know about a cyber security incident involving Beacon, a trusted third-party supplier used by Young Epilepsy and many other charities. We know that news like this may be concerning and being open and transparent with our community is important to us.
There is currently no evidence that any information has been published or misused, and Young Epilepsy is not aware of any fraud or harm linked to this issue.
This update explains what happened, what information may be affected, what we are doing in response, and the steps you can take to stay safe.
What you can find on this page
What happened
Young Epilepsy uses Beacon, a specialist database platform designed for charities, to manage information about children and young people who use our services, people who support our work, and other contacts connected to the charity.
On 3 August 2026, Beacon informed us that it had identified unauthorised access to its systems. The investigation found that copies of database backups were created, which could include information held on behalf of Young Epilepsy. Evidence currently suggests these copies were likely downloaded by an unauthorised party. Beacon is continuing to investigate the incident with the support of independent cyber security specialists and law enforcement agencies and has now published its own FAQs about the incident here: Beacon FAQ
We have reported this situation to the Information Commissioner's Office (ICO) and taken immediate steps to protect our systems.
We are working closely with Beacon to understand the full impact on Young Epilepsy and the the individuals whose information may have been affected, and will continue to keep this page updated as more information becomes available.
What information may be involved
Based on the evidence currently available, the information that may have been affected falls into two broad categories:
- Information that relates to people who receive support from or engage with Young Epilepsy such as contact details and information shared with us to help access support, services or opportunities through Young Epilepsy.
- Information relating to supporters and other contacts, such as names, postal addresses, email addresses, telephone numbers, records of correspondence, event, training or research participation and donation history.
The information held within Beacon does not include bank account details, payment card information or online payment credentials.
We are continuing to work with Beacon to understand exactly what information may have been involved and whether different groups of individuals have been affected in different ways. We will provide further updates on this page as more information becomes available.
What this means for you
We collect and store information on Beacon that helps us support children and young people living with epilepsy and keep in touch with our supporters
Depending on how you engage with Young Epilepsy and the information you choose to share with us, this may include contact details, records of correspondence, event participation, fundraising activity and donation history. It may also include personal information such as date of birth, ethnicity, location, health information, support needs and records of your interactions with us.
This information helps us provide support, communicate with you effectively, understand the impact of our work and continue to improve what we do for children and young people living with epilepsy and their families.
There is currently no evidence that any information has been misused.
However, if personal information has been accessed, there is a risk that it could be used in phishing attempts, such as scam emails, text messages or phone calls from people pretending to be Young Epilepsy or another organisation you trust.
What is phishing?
Phishing is an online scam where a person pretends to be a trusted company or friend to trick you into giving away private information, like your passwords, bank details, or personal data.
What you can do
As a precaution, we recommend that you:
- Be cautious of unexpected emails, text messages, letters or phone calls, particularly if they ask you to click a link, provide personal information or make a payment.
- Remember that Young Epilepsy will never ask you to share passwords, PINs, security codes or full bank card details by email, text message or phone.
- Take extra care to check that any communication claiming to be from Young Epilepsy is genuine before responding.
- If you are ever unsure whether a message or call is legitimate, please contact us directly on dpo@youngepilepsy.org.uk
What we're doing about it
We have taken immediate steps to protect our systems, including:
- Reported the matter to the Information Commissioner's Office (ICO).
- Been working with Beacon to understand the nature and extent of the incident and assess any potential impact on Young Epilepsy data.
- Confirmed that there is no evidence that Young Epilepsy's own systems have been compromised and that this incident relates only to Beacon's systems.
- Reviewing the information held within Beacon to assess the potential impact of data that may have been affected.
- Reviewing and resetting access credentials connected to our Beacon account.
We understand that this news may be concerning. Protecting the information entrusted to us is extremely important, and we are committed to keeping our community informed.
While investigations are ongoing, there is currently no evidence that any information has been published or misused. If our understanding of the issue changes, or if there is any further action we believe people should take, we will update this page and contact affected individuals where appropriate.
If you have any questions or concerns, please contact us at dpo@youngepilepsy.org.uk
Where can you go for advice or support?
Information Commissioner's Office (ICO)
- Independent authority for data protection.
- Families can understand their rights and how personal data breaches are handled.
- Useful if families want reassurance about what organisations should be doing following a breach.
The National Cyber Security Centre (NCSC)
Website: ncsc.gov.uk
Quick links:
Phishing scams - how to spot and report them
Top tips for staying secure online
Report Fraud
UK's Home for Reporting Cyber Crime & Fraud
Website: reportfraud.police.uk
GOV.UK
Report suspicious emails, websites and phishing
Website: gov.uk/report-suspicious-emails-websites-phishing
Young Epilepsy support
Shout 24/7 text support service
Mind
Website: mind.org.uk
Childline
Tel no: 0800 1111
Website: childline.org.uk
The Mix
Website: themix.org.uk
NSPCC Helpline
Tel no: 0808 800 5000 between 10am and 4pm, Monday to Friday
Emailing: help@NSPCC.org.uk between 11am and 4pm, seven days a week
Website: nspcc.org.uk
National Domestic Abuse Helpline (Refuge)
- Phone: 0808 2000 247 (free, 24/7)
- Website: nationaldahelpline.org.uk
FAQs
At present, we cannot confirm whether any specific individual's information has been accessed, viewed or downloaded.
The investigation is ongoing and one of our priorities is to establish whether personal information was accessed and, if so, what information may have been involved.
If we identify that your information has been affected, we will provide you with further information as soon as possible.
The information held within Beacon does not include bank account details, payment card information or online payment credentials.
Our investigation is ongoing. At this stage, we cannot confirm who may have accessed the information or whether any information has been downloaded.
We are working closely with the service provider and relevant experts to establish the facts.
We recognise that uncertainty can be worrying. We are committed to providing updates as soon as we have verified information to share.
This web page will be updated as we learn more.
If our investigation identifies that your information has been affected, we will contact you directly.
On 5 August 2026, we emailed everyone for whom we hold a valid email address and whose information may be affected by this incident.
If you have not received an email from us, it may be because we do not hold a current email address for you, or because the message has been filtered into your junk or spam folder.
For individuals where we only hold a postal address, we carefully considered whether additional communication by post was necessary. Based on the information available, the most likely risk arising from this incident is phishing or scam communications sent by email, text message or phone. We therefore focused our communications on the channels most relevant to that risk.
To ensure everyone has access to the latest information, we are publishing updates and guidance on this web page and will continue to update it as the situation develops.
If you believe your information may be affected and have any questions or concerns, please contact us at dpo@youngepilepsy.org.uk