Data Security Incident: Frequently Asked Questions

What happened? 

On 29 July 2026, Beacon, the third-party provider of the customer relationship management system used by Age Exchange, identified a cyber security incident affecting its systems. Beacon immediately engaged external cyber security specialists to investigate the incident and secure its systems. 

Based on Beacon’s current understanding, unauthorised access was gained through compromised account credentials, and copies of certain database backups were taken. Investigations into the incident remain ongoing.  

Age Exchange was informed of the incident by Beacon on 3 August 2026. Since then, we have been working closely with Beacon to understand the nature and scope of the incident and assess any potential impact on individuals or groups whose information is held within the system.  

We have also conducted our own investigations include a full review of the information potentially affected and we are in the process of contacting anyone who may have been impacted, where appropriate. At this stage, we assess the risk as low to anyone affected and there is no evidence that this information has been published or misused. 

The incident has been reported to the Information Commissioner’s Office, in line with our legal and regulatory obligations. 

Currently, we are not aware of any impact on Age Exchange’s other systems, and our services continue to operate as normal.  

What information may be involved?

Where it has been provided to us, the data involved includes:-  

  • Names 
  • Addresses 
  • Email addresses and telephone numbers 
  • Dates of birth 
  • Gender, Ethnicity and Disability 
  • Emergency contact details 

 
As Beacon cannot yet confirm exactly what data has been impacted, this does not mean that all of this information has been accessed or affected in every case. Our investigations are focused on understanding exactly what information may have been involved and identifying those affected. 

Accordion title 1

This is a placeholder tab content. It is important to have the necessary information in the block, but at this stage, it is just a placeholder to help you visualise how the content is displayed. Feel free to edit this with your actual content.

Accordion title 2

This is a placeholder tab content. It is important to have the necessary information in the block, but at this stage, it is just a placeholder to help you visualise how the content is displayed. Feel free to edit this with your actual content.

What are we doing to address the incident?

Protecting personal information is extremely important to us, and we are taking this matter very seriously. 

As soon as we were notified of the incident, we activated our Critical Incident Response Plan and escalated the matter to senior leaders and specialist external advisers. 

Since becoming aware of the incident, we have: 

  • Reset all Beacon user passwords 
  • Reviewed and reconfigured multi-factor authentication settings 
  • Disabled Age Exchange’s payment links within Beacon as a precautionary measure 
  • Referred the matter to our parent charity’s Information Governance and Data Protection teams 
  • Begun reviewing any requirements to notify commissioners, partners and other stakeholders 
  • Continued to work closely with Beacon and monitor updates from their ongoing investigation 
  • Reported the incident to the Information Commissioner’s Office  

We will continue to take any additional steps necessary to protect personal information and support those who may be affected. 

What happens next?

We will continue to work with Beacon, cyber security specialists and relevant authorities to understand the full circumstances of the incident. 

We have conducted our own review of the information potentially affected and we are in the process of contacting impacted individuals and groups directly, to provide advice and support. At this stage, there is no evidence that this information has been published or misused, and we are not aware of any fraud or harm resulting from this incident. 

We are committed to being open and transparent and will provide updates as more information becomes available. 

If you have any questions or concerns, please email us at hello@ageexchange.org.uk and we will ensure our Data Protection Officer responds as soon as possible. 

What should you do?

At this time, we are not aware of any misuse of personal information connected to this incident. However, as a precaution, we recommend that everyone affected remains vigilant and follows these good security practices: 

  • Be vigilant for unexpected or suspicious emails, text messages, phone calls or letters that appear to come from us or that reference personal details 
  • Do not click on links or open attachments in unsolicited communications. 
  • Never share passwords, verification codes or financial information in response to unexpected requests. 
  • If you receive a communication that appears suspicious, verify it through official channels before responding. 
  • Be cautious of any requests for further personal information or payments that seem unusual.  
  • Check your accounts regularly and report any unusual activity to the relevant provider. 

The Government’s Report Fraud website sets out additional steps that you may wish to take. 

Was any financial or payment information affected?

We do not store any payment card details, bank account information or other financial data in Beacon, so no financial information has been affected.

As a precautionary measure, we have disabled our charity’s own payment links within Beacon while we continue to assess the situation and work with Beacon on their investigation.