School leaders’ information may have been stolen in another massive data leak to hit education. The charity Ark said information about individuals from other organisations may have been stolen following an attack at Beacon CRM. Charities use Beacon to collect donations, manage memberships and sell event tickets. Beacon confirmed it experienced a “cyber-security incident” in which an unauthorised third party gained access to its systems just over two weeks ago. The company believes “the threat actor exported all data contained within the database”. It has told its customers to exercise “an abundance of caution” and “review the data potentially impacted and consider whether you need to notify your contacts”. A spokesperson said the company immediately got help from cybersecurity experts who contained the incident and launched an investigation. It had not seen any ongoing unauthorised access and its customers could access its platform and services as normal. Ark member warning Ark revealed that it and EdCity – a complex in west London it oversees – used Beacon. It did not use the system to store banking or payment card details. However, “limited contact information” – such as names, numbers and addresses – of some individuals “at schools, trusts and external partners” who signed up as EdCity “members” may have been taken. Members use the building’s co-working spaces, event and networking opportunities, and get subsidised rates for its venues. EdCity’s website lists the Department for Education (DfE) alongside multi-academy trusts United Learning, Lift Schools and Ormsiton as some of its members. Schools Week is a tenant. Ark – which sponsors the Ark Schools academies trust – said it did not “maintain comprehensive contact lists or broader personal data for entire organisations or trusts”. Its own school and trust data were held in separate systems. Watchdogs called The Charity Commission issued its own guidance to affected organisations “given the nature of this incident and the number of charities that may be affected”. The Information Commissioner’s Office (ICO) said it had received a number of reports about the incident. It was in contact with Beacon. Schools Week approached 14 other leading education charities. Seven said they did not use Beacon, while the rest did not respond to our approach. Separately, the Boards of Education, a governance charity, revealed on Wednesday it had discovered “unauthorised access to part of our website where… user registration information is stored”. In an email to account holders, it said names and email addresses may have been accessed during the incident. It asked all of its users to “reset their password as an additional precaution”. A spokesperson stressed no passwords or financial records were accessed. It has notified the ICO and DfE and is “conducting a thorough investigation with our website host to ascertain how this happened and what lessons can be learned”. DfE attack The breach comes after the names and contact details of school leaders were among more than 600,000 records stolen in a cyber-attack that targeted the DfE’s help portal and Turing Scheme database two weeks ago. And last year, school staff were told they faced increased risk of identity theft after their personal details were “compromised” following an incident involving the software supplier of Single Central Record (SCR). In 2024, Ofqual warned schools that scores of children’s coursework could be lost after it was found that one in three secondaries had been rocked by cyber-attacks over the previous 12 months.