Beacon CRM data breach
Beacon, a CRM platform used by more than a thousand UK charities, confirmed that an attacker used an AWS access key exposed in the company's public JavaScript to copy and exfiltrate its entire customer database of supporter and donor records.
- Victim
- Beacon (Beacon CRM)
On 12 August 2026, Beacon β a customer-relationship-management (CRM) platform used by more than a thousand UK charities and non-profit organisations β disclosed that an attacker had made a complete copy of its customer database and exfiltrated it. The intrusion stemmed from an Amazon Web Services (AWS) access key that had been exposed in publicly accessible JavaScript build artifacts on the company's own website.
What happened
The disclosure, issued by Beacon's chief technology officer, traced the breach to a leaked AWS access key. The credential had been inadvertently baked into client-facing JavaScript β the kind of mistake that occurs when automated build tooling embeds environment variables or secrets into code shipped to browsers, leaving them readable by anyone who inspects the site.
Investigators found the earliest malicious activity on 27 July 2026 at around 01:20 UTC. The attacker operated for roughly 1 hour and 27 minutes before access was closed. A sharp spike in data transfer matching the total volume of stored platform records led Beacon to conclude that the entire database and attachment files had been exported.
The compromised data included supporters' and donors' names, email addresses, phone numbers, postal addresses, donation records and attachments. Beacon said the breach did not include payment-card, bank-account or patient data.
Impact
- Personal data of supporters and donors across more than 1,000 UK charities β with some reporting putting the figure at over 1,500 organisations β was exposed.
- Affected sectors include healthcare-related and victim-support charities, raising the sensitivity of the exposed donor relationships.
- No financial or payment data was reported compromised.
Why it matters
The Beacon breach is a compact case study in two persistent failures. First, secret exposure in front-end code: an AWS key shipped to browsers is effectively public, and a single over-privileged credential was enough to copy an entire multi-tenant database in under 90 minutes. Second, shared-platform (supply-chain) concentration: charities that never suffered their own intrusion nonetheless lost supporter data because they relied on a common CRM. For non-profits, whose donor relationships depend on trust and whose security budgets are thin, the incident is a reminder that vendor due diligence and least-privilege credential management are not optional extras but core donor-protection controls.
Timeline
Earliest malicious activity recorded at 01:20 UTC; the attacker operates for roughly 1 hour 27 minutes before access is closed, exporting a data volume matching the full platform database.
Beacon's CTO publicly discloses that a threat actor made a complete copy of and exfiltrated the customer database.
Sources
- securityweek.comhttps://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/exposed-aws-key-data-charities/
- cybersecuritynews.comhttps://cybersecuritynews.com/beacon-crm-database-theft/
- rescana.comhttps://www.rescana.com/post/beacon-crm-data-breach-exposes-personal-data-of-over-1-000-uk-charities-in-aws-credential-compromise