Beacon CRM breach exposed backups of 1,000+ charities
Beacon, a UK CRM for charities, reported attackers used a compromised AWS access key to export encrypted database backups for more than 1,000 customers on July 27–28.
Beacon, a UK provider of customer relationship management software for charities, reported that attackers used a compromised Amazon Web Services access key to download encrypted database backups for more than 1,000 customers. The company observed the first malicious activity on July 27 and assessed that data transfers likely occurred on July 27–28.
“Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs,” the company noted. “However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database.”
Beacon’s investigation found the access key may have been exposed in publicly available JavaScript build artifacts, allowing the actor to access the cloud environment and copy backups. No criminal group has been publicly linked to the incident and the company is not aware of the stolen data being published.
Several UK charities that use Beacon confirmed they were affected. Some reported that personal information for supporters, including names, phone numbers, email addresses and postal addresses, may have been included in the downloaded backups. Other organisations noted that bank account numbers, sort codes, card numbers and card security codes are not stored in Beacon and therefore were not exposed.
The Charity Commission for England and Wales is monitoring the incident and has issued guidance for charities on how to protect supporters’ data and report suspected breaches. Beacon has notified customers, is working to secure its systems, and is assisting affected organizations.
Security teams have increasingly found exposed credentials and build artifacts in cloud environments are used to gain access to stored data, and Beacon’s finding that an access key may have been exposed in public JavaScript files follows that trend.








