Beacon CRM breach likely exposed donor and service-user data across UK charities

Beacon CRM says attackers likely copied and downloaded database backups, potentially exposing data stored by UK charities that use its platform. The company says early evidence points to compromised credentials, became aware of the incident on July 29, and is telling customers to assume all data in paid or trial accounts created before July 27 may have been taken, including attachments; Beacon also reset all user passwords.
Why it matters: This is a supply-chain-style vendor breach for the charity sector, so one intrusion may affect many organizations and the people they support. Charities using Beacon should treat stored data as exposed, review what was held there, notify affected people as needed, and watch for phishing or fraud targeting donors, supporters, and service users.

Sources

Over 1,000 Charities Hit by Beacon CRM Data Breach
Eduard Kovacs 2026.08.14 98% relevant
This is a direct update on the same Beacon CRM breach, adding that the likely root cause was a compromised AWS access key exposed in public JavaScript build artifacts, narrowing the timeline to July 27-28 and stating Beacon believes the attacker likely exported all database data across its more than 1,000 customers.
AWS key exposed in JavaScript may have lit way to Beacon's charity data
2026.08.13 98% relevant
This is a direct update on the same Beacon breach, adding Beacon's stated likely root cause (an AWS access key exposed in public JavaScript build artifacts), confirmation that a full customer database copy was made and likely downloaded in readable form, and evidence from AWS Cost & Usage reports showing unusual data transfer on July 27-28.
UK charities count the cost of Beacon CRM cyberattack
2026.08.05 100% relevant
This article appears to be the first clear report establishing the Beacon CRM incident as a multi-charity breach with likely exfiltration of customer database backups and broad downstream exposure.
← Back to all stories