Skip to content
3 September 2026

Exclusive

School leaders hit in cyber attack on charity services company

Education charity Ark impacted after tech company rocked by major data leak
3 min read
|

School leadersinformation may have been stolen in another massive data leak to hit education.

The charity Ark said information about individuals from other organisations may have been stolen following an attack at Beacon CRM.

Charities use Beacon to collect donations, manage memberships and sell event tickets.

Beacon confirmed it experienced a cyber-security incident in which an unauthorised third party gained access to its systems just over two weeks ago.

The company believes “the threat actor exported all data contained within the database”. 

It has told its customers to exercise “an abundance of caution” and “review the data potentially impacted and consider whether you need to notify your contacts”. 

A spokesperson said the company immediately got help from cybersecurity experts who contained the incident and launched an investigation.

It had not seen any ongoing unauthorised access and its customers could access its platform and services as normal.

Ark member warning

Ark revealed that it and EdCity a complex in west London it oversees used Beacon.

It did not use the system to store banking or payment card details.

However, limited contact information” – such as names, numbers and addresses of some individuals at schools, trusts and external partnerswho signed up as EdCity membersmay have been taken.

Members use the buildings co-working spaces, event and networking opportunities, and get subsidised rates for its venues.

EdCitys website lists the Department for Education (DfE) alongside multi-academy trusts United Learning, Lift Schools and Ormsiton as some of its members. Schools Week is a tenant.

Ark which sponsors the Ark Schools academies trust said it did not maintain comprehensive contact lists or broader personal data for entire organisations or trusts. Its own school and trust data were held in separate systems.

Watchdogs called

The Charity Commission issued its own guidance to affected organisations given the nature of this incident and the number of charities that may be affected.

The Information Commissioners Office (ICO) said it had received a number of reports about the incident. It was in contact with Beacon.

Schools Week approached 14 other leading education charities. Seven said they did not use Beacon, while the rest did not respond to our approach.

Separately, the Boards of Education, a governance charity, revealed on Wednesday it had discovered “unauthorised access to part of our website where… user registration information is stored”.

In an email to account holders, it said names and email addresses may have been accessed during the incident. It asked all of its users to “reset their password as an additional precaution”.

A spokesperson stressed no passwords or financial records were accessed. It has notified the ICO and DfE and is “conducting a thorough investigation with our website host to ascertain how this happened and what lessons can be learned”.

DfE attack

The breach comes after the names and contact details of school leaders were among more than 600,000 records stolen in a cyber-attack that targeted the DfEs help portal and Turing Scheme database two weeks ago.

And last year, school staff were told they faced increased risk of identity theft after their personal details were compromisedfollowing an incident involving the software supplier of Single Central Record (SCR).

In 2024, Ofqual warned schools that scores of childrens coursework could be lost after it was found that one in three secondaries had been rocked by cyber-attacks over the previous 12 months.

Share

Explore more on these topics

No Comments

Featured jobs from FE Week jobs / Schools Week jobs

Browse more news