Beacon CRM Data Breach Exposes Entire Customer Database After AWS Key Compromise
Brief
Beacon CRM, a customer relationship management platform used by more than 1,000 UK charities and non-profit organisations, has confirmed that an attacker copied and exfiltrated its entire customer database following the compromise of an Amazon Web Services (AWS) access key .
The updated disclosure, issued by Chief Technology Officer David Simpson on August 12, 2026, significantly expands on Beacon’s earlier statements.
A forensic investigation conducted with external cybersecurity specialists determined that the compromised cloud credential enabled unauthorised access to platform data and attachment files stored in the company’s AWS environment.
Beacon CRM Data Breach
The key had been exposed in publicly accessible JavaScript build artifacts hosted on Beacon’s website.
