2026 Beacon CRM — company-confirmed backup theft; UK charity donor/supporter data at risk
Data compromised
Per Beacon: assume all customer CRM data and attachment files in accounts created before July 27, 2026 may have been downloaded (encrypted at rest but possibly decrypted). Charity notices cite supporter/donor/service-user names, addresses, emails, phones, genders, dates of birth, and donation/payment records. Beacon says no evidence card details compromised.
Technical writeup
Verified company disclosure — late July / early August 2026. UK charity CRM vendor Beacon CRM confirmed an unauthorized third party accessed its systems using a compromised access key more sophisticated than a simple username/password. Beacon says investigation evidence shows database backups were copied and likely downloaded, with activity spikes consistent with data leaving its environment; customers are told to assume all data stored in Beacon—including attachment files—for paid accounts or free trials created before July 27, 2026 may have been downloaded, and that although data is encrypted at rest it may have been decrypted. Beacon became aware around July 29, 2026, reset passwords, remapped AWS credentials, and reported deploying SentinelOne EDR/CNS with no ongoing unauthorized access observed after containment. The Register (August 5) reported more than 1,500 charity customers and named affected organizations including the Molly Rose Foundation, The Upper Room, Chiswick House and Gardens Trust, Macmillan Cancer Support Jersey, Motiv8, UK-Med, and English National Ballet (precautionary notice). Victim Support stated no victim data was affected on its tenancy. Aggregate individual headcount not published — recordsAffected 0 pending census/ICO filings.
Root cause
Unauthorized access via compromised access key; database backups copied and likely downloaded; Beacon warns data may have been decrypted