Beacon CRM said a cyberattack exposed data belonging to a significant number of UK charities that use its platform, after attackers copied database backups and likely downloaded them. The company warned customers to assume that all data stored in Beacon before July 27, including attachments, was taken, and said the information may be readable even where customer data had been encrypted. Beacon discovered the incident around July 29 and began notifying affected customers on August 3.
Early evidence indicates the attackers gained access using compromised credentials, although Beacon has not disclosed how the credentials were obtained or whether extortion demands were made. In response, the company reset all user passwords and tightened password requirements, while affected organizations including the Molly Rose Foundation assessed potential exposure of donor, supporter, and service-user information; Victim Support said its victim data was not affected.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
Beacon said a potentially exposed AWS access key in public JavaScript build artifacts is the leading suspected cause of its July 2026 breach. The company said malicious activity began in the early hours of July 27, lasted 1 hour and 27 minutes, and correlated with increased AWS data transfer on July 27-28, supporting its assessment that a copy of the customer database and attachments was likely downloaded.
ITV News Channel reported that ten charities in the Channel Islands disclosed data breaches tied to the Beacon CRM cyber incident, expanding the known set of affected organizations beyond those already named. This represents a further victim disclosure linked to the same Beacon compromise.
LawCare said on August 4 that it was affected by the Beacon CRM cyberattack and warned people in its database to stay alert for phishing and suspicious communications. The charity said Beacon-held data related to callers, supporters, donors, volunteers, and fundraising contacts may have been downloaded, but no bank account or payment card details were stored there.
Guild Care said Beacon informed it of the incident on August 3 and disclosed that names, email addresses, and organizational information held in Beacon may have been affected; it began notifying impacted contacts and assessing whether to report the incident to the UK ICO. The British Deaf Association, Saints Foundation, and Full Fact also reported being affected by the Beacon CRM breach.
Beacon CRM started notifying affected customers on August 3. The Molly Rose Foundation said Beacon informed it of the breach that day.
Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice, and The Clock Tower Sanctuary were identified as charities whose Beacon-hosted databases were potentially accessed in the incident. Their disclosure expanded the known list of affected organizations in the healthcare and homelessness sectors.
Beacon CRM became aware of the breach around July 29, according to affected-customer statements and subsequent reporting. Early evidence indicated the attackers accessed Beacon systems using compromised credentials.
Beacon CRM warned that anyone with a paid account or free trial created before July 27 should assume all data stored in Beacon before that date, including attachments, was downloaded by an unauthorized third party and may be readable despite encryption.
Victim Support, identified among affected charities using Beacon CRM, stated that no victim data was impacted by the incident.
The Molly Rose Foundation said personal data belonging to supporters, donors, and service users was affected, including names, addresses, email addresses, phone numbers, genders, dates of birth, and donation or payment records.
Beacon CRM publicly confirmed a cyberattack affecting customer data from UK charities, said database backups were copied and likely downloaded, and advised customers to assume all stored platform data may have been compromised. The company also reset all user passwords and imposed stronger password requirements while its investigation continued.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourceitv.com
Open sourceinfosecurity-magazine.com
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.