Beacon, a CRM platform utilized by over a thousand UK charities, has revealed a significant data breach involving the theft of its entire customer database. This disclosure was made by CTO David Simpson on August 12, 2026, marking a critical update from previous communications.
Investigation and Breach Details
A thorough forensic investigation, conducted with cybersecurity experts, traced the breach to a compromised Amazon Web Services (AWS) access key. The key was inadvertently made public through JavaScript build artifacts on Beacon’s website. Such leaks can occur when environment variables or secret keys are included in code that becomes publicly accessible.
This exposure allowed unauthorized access, enabling the attacker to exfiltrate the database. The breach aligns with patterns seen in credential phishing attacks and automated scans targeting exposed cloud resources.
Timeline and Impact of the Data Theft
The official incident report from Beacon CRM indicates that the attack commenced on July 27, 2026. The unauthorized access lasted approximately 87 minutes, during which the entire database, including attachment files, was exfiltrated. AWS Cost and Usage reports confirmed a spike in data transfer on July 27 and 28, 2026, corroborating the database theft.
Despite maintaining data encryption at rest, the stolen AWS access key enabled the attacker to decrypt and download the data, as AWS decrypts data for valid credential holders automatically.
Response Actions and Regulatory Involvement
Beacon has taken several measures to address the breach: all AWS keys were revoked and rotated, sensitive data was removed from client-side scripts, and enhanced security tools were deployed across the enterprise. These actions aim to prevent future breaches and secure the infrastructure.
The incident has prompted investigations by the UK Charity Commission, the ICO, and Action Fraud. Affected organizations like Justice for Colombia and the Center for Sustainable Energy have started informing stakeholders about potential data exposure.
Beacon continues to monitor for any signs of the stolen data being sold or misused and advises clients to assess their notification obligations. A comprehensive report on the breach is forthcoming.
