Last Update: 09/21/2026 at 5:00 AM EST

Beacon CRM Breach Hits UK Charities

Coverage from BankInfoSecurity, Rescana, and others

Beacon CRM Breach Hits UK Charities topic image

A compromised Beacon CRM credential, reportedly an AWS access key exposed in public JavaScript build artifacts, allowed unauthorized access to database backups and customer information associated with more than 1,000 UK charities and nonprofits.

The incident may have exposed contact details, donation records, operational information, and attachments, although the exact dataset accessed and the presence of highly sensitive records remain uncertain. Beacon and affected organizations are investigating, notifying regulators and individuals, and warning about potential phishing.

Looking Back
13 Day Timeline
Aug 5Aug 7Aug 10Aug 12Aug 15Aug 17
History
08/24/2026

The incident is now more specifically linked to an AWS access key exposed in public JavaScript artifacts, with reporting indicating that encrypted backups were downloaded or copied on July 27–28. Limited logging means Beacon cannot determine exactly which records were accessed or where copies went, preserving substantial uncertainty about the breach’s scope.

All Articles8 articles
Additional8 articles · CI Score below 45
BankInfoSecurity / Mathew J. Schwartz
8/5/2026 • Data Breaches & Exposure Events • General
Rescana
8/17/2026 • Data Breaches & Exposure Events • General
Yahoo
8/5/2026 • Data Breaches & Exposure Events • General
SecurityWeek / Eduard Kovacs
8/14/2026 • Data Breaches & Exposure Events • General
Guild Care
8/6/2026 • Data Breaches & Exposure Events • General
Daily Security Intel
8/15/2026 • Cybersecurity (Privacy-Relevant) • General
Canadian Lawyer / Jacqueline So
8/11/2026 • Data Breaches & Exposure Events • General
Bailiwick Express
8/11/2026 • Data Breaches & Exposure Events • General