HackMyIP
← Back to News
2026-08-14 SecurityWeek

Beacon CRM Breach Exposes Data of 1,000+ UK Charities

Data BreachCloud SecuritySupply Chain

Beacon, a UK-based customer relationship management (CRM) provider serving the non-profit sector, has disclosed that a data breach impacting more than 1,000 charities stemmed from a compromised AWS access key that may have been exposed in publicly available JavaScript build artifacts. The company first revealed the incident in early August, reporting that attackers had downloaded customer database backups from its AWS environment. While the data was encrypted at rest, Beacon warned that the threat actor could have decrypted it prior to exfiltration, raising significant concerns about the exposure of donor and supporter records.

According to Beacon's latest update, the earliest malicious activity was logged on July 27, with the data transfer likely occurring on July 27–28. The company's investigation determined that "specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs," but assessed that the threat actor exported all data contained within the database. Several affected UK charities have since confirmed that personal information belonging to supporters—including names, phone numbers, email addresses, and postal addresses—may have been compromised. Beacon emphasized that no bank account numbers, sort codes, card numbers, or card security details were exposed, as such financial information is not stored on its platform.

The UK's Charity Commission is monitoring the situation and has issued guidance to affected organizations. No known cybercrime group has claimed responsibility for the attack, and Beacon says it is not aware of the stolen data being published. The incident underscores the ongoing risks of exposed cloud credentials in build artifacts and the cascading impact of supply-chain breaches on downstream organizations. Charities and their supporters can verify whether their email addresses appear in known incidents using an email breach checker, while organizations should audit their AWS access key management practices and review exposure in publicly accessible repositories. For broader hygiene, a password checker can help identify credentials that may need rotation following supply-chain compromises of this nature.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →