← Beacon CRM

2026 Beacon CRM — company-confirmed backup theft; UK charity donor/supporter data at risk

2026 Unknown records affected Share on X

Data compromised

Per Beacon: assume all customer CRM data and attachment files in accounts created before July 27, 2026 may have been downloaded (encrypted at rest but possibly decrypted). Charity notices cite supporter/donor/service-user names, addresses, emails, phones, genders, dates of birth, and donation/payment records. Beacon says no evidence card details compromised.

Technical writeup

Verified company disclosure — July 27–August 19, 2026. UK charity CRM vendor Beacon CRM confirmed unauthorized access via a compromised AWS access key (Beacon’s August 12–19 updates say the key may have been exposed in publicly available JavaScript build artifacts). Malicious activity began 27 July; data likely transferred 27–28 July. Beacon assesses the threat actor exported essentially all database contents including attachment files for 1,000+ charity customers (CTO update: copy made and likely downloaded in readable form despite encryption at rest). SecurityWeek (19 August) summarized the AWS-key/JS-artifact root cause and Charity Commission guidance. Customers told to assume supporter/donor/service-user CRM data may be out; no card/bank details in Beacon per vendor. recordsAffected 0 pending ICO aggregate census.

Root cause

Unauthorized access via compromised access key; database backups copied and likely downloaded; Beacon warns data may have been decrypted

References