Beacon CRM has confirmed a data breach after a compromised AWS access key was used to copy customer database backups, potentially affecting around 1,500 UK charities.[2][6][11] The incident has alarmed organizations across the UK charity sector that rely on Beacon to manage donor, supporter, and service user data in sensitive areas such as healthcare and victim support.[6][7][13]
Beacon says its current investigation indicates that an AWS access key was used to gain unauthorized access to its cloud environment, in what it describes as a more sophisticated intrusion than simple credential theft.[2][6] The key is believed to have been exposed in publicly accessible JavaScript build artifacts on Beaconβs own site, providing a path for an attacker to authenticate directly to its Amazon Web Services infrastructure.[1][4] According to timelines shared with customer organizations, the earliest confirmed malicious activity occurred around 01:20 UTC on 27 July 2026 and lasted for roughly ninety minutes.[4]
During that window, the attacker made copies of Beaconβs database backups, which Beacon and several affected charities say were likely downloaded in readable form.[1][2][4] The stolen data sets include names, email addresses, telephone numbers, donation histories and other supporter records, with some organizations reporting exposure of Gift Aid declarations and attachment files.[6][11] Beacon has emphasized that data stored in its AWS environment was encrypted at rest, but acknowledges that the compromised access key appears to have allowed the threat actor to retrieve that information in a decrypted state.[1][2]
Beacon reports that the incident has been contained with the help of external cybersecurity specialists, who have not observed any ongoing unauthorized access to its AWS environment or developer endpoints since the initial breach window.[2][6] The company says it has remediated the root cause, reset all credentials for services integrated with AWS, and notified all affected customer charities, which are now working through their own regulatory and communications obligations.[2][6] The UK government has issued guidance for charities caught up in the Beacon cyber security incident, advising them on steps to assess impact, communicate with donors and service users, and engage with relevant regulators.[10]
So far, Beacon and sector commentators say there is no evidence that the stolen data has been published on the dark web, and no ransomware demand has been publicly disclosed, although the scale of the data theft has led some observers to treat it as a serious extortion risk.[6][7][11] Beacon has stated that customers can continue using its forms to collect payments, provided they follow its incident response guidance to update payment providers and integrated applications, but many charities are nonetheless reviewing their dependence on a single CRM platform for core fundraising and casework functions.[2][6][7]
The breach underscores the systemic risk created when long-lived cloud access keys are embedded in build artifacts or client-side code, particularly in multi-tenant SaaS platforms handling sensitive personal data. Charity security teams responding to the Beacon incident are being urged by advisers to rotate all credentials tied to the platform, ingest SaaS audit logs into their own monitoring tools, and press vendors for detailed answers on access vectors and indicators of compromise.[7] More broadly, the episode is likely to fuel fresh scrutiny of how non-profit technology providers design and secure their cloud architectures, and how regulators expect charities to manage third-party risk when donor and beneficiary data are concentrated in shared CRM services.[6][7][10]
References
- AWS key exposed in JavaScript may have lit way to …
- Incident FAQs
- Beacon CRM Data Security Incident – Sudden Cardiac Arrest UK
- Healthcare and Victim Support Charities Affected by …
- Beacon CRM Breach: 1,500 Charities’ Data Exfiltrated β Third-Party Detection and Response Playbook
- Guidance for charities affected by the Beacon cyber security incident
- Beacon CRM Data Breach: Helpful Pointers
- Healthcare and Victim Support Charities Affected by …