Beacon CRM Cyberattack Exposes UK Charity Donor Data
A cyberattack on Beacon CRM has compromised sensitive data belonging to over 1,500 UK charities, including donor and service user information.

Beacon CRM, a platform widely used by UK charities, has confirmed it was the target of a significant cyberattack that resulted in the exposure of sensitive customer data. The breach, discovered around July 29, has prompted Beacon to warn its users to assume that all data stored on the platform, including potentially decryptable encrypted information, was copied and downloaded by unauthorized third parties.
In a statement, Beacon indicated that its investigation confirmed "copies of database backups were made and likely downloaded by the unauthorized third-party." The company also noted "a spike in activity during the incident timeline symptomatic of data leaving our systems." Due to the inability to ascertain the exact nature and scope of the exfiltrated data, Beacon is advising all customers with paid accounts or free trials created before July 27 to assume that all their stored data, including attachments, has been compromised.
While Beacon CRM encrypts customer data, the company has cautioned that the attackers may have been able to decrypt it. This means that sensitive information, such as names, addresses, contact details, donation records, and personal service user information, could now be in the hands of malicious actors. Beacon has not disclosed details regarding the method of intrusion or whether any extortion demands have been made, but early evidence suggests compromised credentials may have been used to gain access.
As a precautionary measure, Beacon has reset all user passwords and implemented stricter requirements for new passwords. Affected charities are urged to conduct their own assessments to understand the full extent of the impact on their operations and constituent data. The incident response is ongoing, with Beacon working to provide further clarity as its investigation progresses.
Several high-profile UK charities have confirmed they were impacted. The Molly Rose Foundation, an advocate for the UK's Online Safety Act, reported being notified by Beacon on August 3rd and confirmed that personal data of its supporters, donors, and service users was affected. Other confirmed victims include the Scottish Council for Voluntary Organisations (SCVO), The Upper Room, Chiswick House and Gardens Trust, Victim Support (though no victim data was affected), Macmillan Cancer Support Jersey, Motiv8, UK-Med, and the English National Ballet.
The attack highlights the vulnerability of specialized software platforms serving critical sectors like charities. The reliance of these organizations on such tools means that a single breach can have far-reaching consequences, impacting not only the organizations themselves but also the individuals they serve and support. The potential for decryption of sensitive data amplifies the risk of identity theft, fraud, and further targeted attacks against individuals whose information was compromised.
Beacon CRM's focus on the charity sector means that the majority of affected entities are UK-based non-profits. This incident underscores the need for robust security measures within the technology providers that underpin the operations of these vital organizations. The ongoing investigation aims to shed more light on the attack vector and the full scope of the data breach, but the immediate advice remains to treat all data as compromised.
Beacon CRM has confirmed that compromised credentials were used to gain unauthorized access to its systems, leading to the exfiltration of customer data, including database backups. The company has warned customers that it may be impossible to determine the exact volume of data stolen and advises assuming all stored data, including attachments, may have been downloaded by attackers.
The cyber incident impacting Beacon CRM has now been confirmed to have affected approximately 1500 UK charities, including those in sensitive sectors like healthcare and victim support. While the CRM provider stated that payment card details and bank account information were not compromised, evidence suggests that names, email addresses, telephone numbers, and donation records were exfiltrated by an unauthorized actor who gained access via a compromised access key.
Beacon CRM has provided an update on the July breach, identifying a potentially exposed AWS access key in public JavaScript build artifacts as the leading suspect. The company confirmed that a copy of the entire customer database, including attachments, was made and likely downloaded in a readable format. Analysis of AWS cost reports shows a significant spike in data transfer correlating with the incident timeline, supporting the assessment of substantial data exfiltration.
The compromised AWS access key was potentially exposed in public Javascript build artifacts, indicating a development error. Malicious activity was detected between July 27 and July 28, lasting for approximately one hour and 27 minutes, during which the attacker accessed and downloaded all data within the CRM platform. Beacon has reset all integrated service and account credentials to prevent recurrence and has not detected any attempts by the threat actor to maintain persistence.
Beacon CRM has now confirmed that the full customer database, including attachment files, was exfiltrated by the threat actor. The breach occurred due to a compromised AWS access key that was inadvertently exposed in public JavaScript build artifacts on their website. While the data was encrypted at rest, the attacker used the valid AWS credentials to decrypt and download the entire database, bypassing this protection.
Beacon CRM has provided an update on the data breach, revealing that the earliest malicious activity was observed on July 27th, with data likely exfiltrated between July 27th and 28th. The investigation points to a compromised AWS access key, inadvertently exposed in public JavaScript build artifacts, as the likely vector for unauthorized access to the database. While the exact scope of accessed objects remains undetermined, the company assesses that all data within the database was exported.