Beacon CRM Breach Hits UK Charities
Coverage from BankInfoSecurity, Rescana, and others

A compromised Beacon CRM credential, reportedly an AWS access key exposed in public JavaScript build artifacts, allowed unauthorized access to database backups and customer information associated with more than 1,000 UK charities and nonprofits.
The incident may have exposed contact details, donation records, operational information, and attachments, although the exact dataset accessed and the presence of highly sensitive records remain uncertain. Beacon and affected organizations are investigating, notifying regulators and individuals, and warning about potential phishing.
The incident is now more specifically linked to an AWS access key exposed in public JavaScript artifacts, with reporting indicating that encrypted backups were downloaded or copied on July 27–28. Limited logging means Beacon cannot determine exactly which records were accessed or where copies went, preserving substantial uncertainty about the breach’s scope.
