Beacon disclosed that attackers used a compromised AWS access key exposed in publicly accessible JavaScript build artifacts to access its CRM platform and exfiltrate a full copy of customer data. The company said the intrusion targeted its entire customer base of roughly 1,500 UK charities and non-profits, with malicious activity beginning on July 27 and lasting about 1 hour and 27 minutes, matching a sharp spike in AWS data transfers. Because the attacker authenticated with valid credentials, data encrypted at rest was reportedly downloaded in readable form.
Exposed information may include supporters’ names, email addresses, phone numbers and donation records, affecting charities in sensitive sectors including healthcare and victim support; Beacon said patient data, payment card data and bank account information were not stored in the compromised CRM environment. The company reported no evidence of persistence, rotated AWS-integrated credentials, removed secrets from client-side assets, added security tooling, and notified UK regulators and law enforcement, while affected organizations such as Justice for Colombia and the Center for Sustainable Energy began warning supporters of potential exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-13, The Survivor’s Trust said the UK Information Commissioner’s Office had reviewed its case and concluded the charity bore no responsibility for the Beacon breach. The charity also urged supporters to stay alert for scams.
On 2026-08-12, Beacon disclosed through CTO David Simpson that a compromised AWS access key exposed in public JavaScript build artifacts likely enabled the theft of its CRM data. Beacon said the attacker used valid credentials, making encrypted-at-rest data readable when downloaded.
Reporting on the Beacon CRM breach identified additional affected organizations, including GuildCare, Saints Foundation, and Full Fact, alongside previously named charities. The organizations were described as notifying impacted individuals and assessing what data in their Beacon environments was exposed.
Affected charities and reporting on Beacon’s incident said the breach impacts all of Beacon’s more than 1,000 customer organizations. This expanded the known scope of the incident across UK charity and nonprofit users of Beacon’s CRM platform.
Beacon's investigation identified a major increase in AWS data downloads and transfer between July 27 and July 28, 2026, matching the volume of stored records and attachments. This activity aligned with the suspected exfiltration window.
Beacon said the earliest malicious activity began on 2026-07-27 at 01:20:16 UTC after an exposed AWS access key was used to authenticate to AWS. The activity lasted about 1 hour and 27 minutes, and investigators concluded the attacker exported the full customer database and attachment files.
Downstream charities publicly warned supporters that personal information and donation histories may have been compromised through the Beacon breach. Named organizations included The Survivor’s Trust, Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire's Brain Tumour Charity, Justice for Colombia, and the Center for Sustainable Energy.
Beacon reported the incident to UK regulators and law enforcement, with the Information Commissioner’s Office, the Charity Commission, and Action Fraud becoming involved. Beacon also advised affected charities to assess and fulfill their own notification obligations.
After the breach, Beacon revoked and rotated AWS-integrated credentials, removed sensitive build parameters from client-side JavaScript, and deployed additional security tooling including endpoint detection and SentinelOne Cloud Native Security. Beacon also said it found no evidence of persistence in its environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceteiss.co.uk
Open sourcecybersecuritynews.com
Open sourceinfosecurity-magazine.com
Open sourcebeaconcrm.org
Open sourcelawcare.org.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.