Beacon CRM Confirms Full Database Theft After AWS Access Key Breach
Brief
Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a threat actor made a complete copy of and exfiltrated its customer database.
The disclosure, released by Chief Technology Officer David Simpson on August 12, 2026, marks a major escalation from initial statements and clarifies the full scale of the compromise.
According to Beacon’s forensic investigation conducted alongside external cybersecurity specialists, the intrusion stemmed from a compromised Amazon Web Services (AWS) access key.
The sensitive credential was exposed within publicly accessible JavaScript build artifacts hosted directly on the company’s website.
