Open Road uses a supplier called Beacon to manage our supporter records. Beacon recently informed us late July 2026, that an unauthorised third party gained access to their systems and may have copied your data held on their platform.
The information we hold about you through this platform is limited to contact details such as your name, address, email address and phone number, and does not include any payment or banking information.
Beacon believes the most likely cause was a compromised access key which allowed the attacker to access its Amazon Web Services (AWS) environment. While we have no evidence that your information has been misused, we want to be open with you and suggest a few simple precautions:
• Be cautious of any unexpected calls, emails, or letters claiming to be from Open Road, particularly ones asking you to click a link, confirm personal details, or make a payment.
• Never share passwords, PINs, or bank details in response to an unsolicited request.• If anything feels off about a message claiming to be from us, contact us directly using the details on our website to check it’s genuine, rather than replying to the message itself.
Beacon have set up briefing pages on their website for affected people:
They also have a dedicated email address for specific followup questions about the incident: incident@beaconcrm.org
We take the security of your information seriously and are reporting this matter to the Information Commissioner’s Office and reviewing our own data retention practices as a result. if you have any questions or concerns, please don’t hesitate to contact us. We are very sorry that this has happened and for any concern it may cause. It is our understanding that Beacon is widely used by charities and organisations affected by this cyber-security incident.
Thank you for your continued support of Open Road.

