2026 Beacon CRM — company-confirmed backup theft; UK charity donor/supporter data at risk
Data compromised
Per Beacon: assume all customer CRM data and attachment files in accounts created before July 27, 2026 may have been downloaded (encrypted at rest but possibly decrypted). Charity notices cite supporter/donor/service-user names, addresses, emails, phones, genders, dates of birth, and donation/payment records. Beacon says no evidence card details compromised.
Technical writeup
Verified company disclosure — July 27–August 19, 2026. UK charity CRM vendor Beacon CRM confirmed unauthorized access via a compromised AWS access key (Beacon’s August 12–19 updates say the key may have been exposed in publicly available JavaScript build artifacts). Malicious activity began 27 July; data likely transferred 27–28 July. Beacon assesses the threat actor exported essentially all database contents including attachment files for 1,000+ charity customers (CTO update: copy made and likely downloaded in readable form despite encryption at rest). SecurityWeek (19 August) summarized the AWS-key/JS-artifact root cause and Charity Commission guidance. Customers told to assume supporter/donor/service-user CRM data may be out; no card/bank details in Beacon per vendor. recordsAffected 0 pending ICO aggregate census.
Root cause
Unauthorized access via compromised access key; database backups copied and likely downloaded; Beacon warns data may have been decrypted
References
- https://www.beaconcrm.org/incident-faqs
- https://www.beaconcrm.org/incident-guidance
- https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/
- https://www.theregister.com/security/2026/08/13/aws-key-exposed-in-javascript-may-have-lit-way-to-beacons-charity-data/5287303
- https://www.gov.uk/government/news/guidance-for-charities-affected-by-the-beacon-cyber-security-incident