[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSsQHYp4e-7XoPsweZnlcOd64FmkEY524RbLOS2YV0zo":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"0e51bc8c-7413-4eb4-b349-9130741fc1aa","Over 1,000 Charities Hit by Beacon CRM Data Breach","over-1-000-charities-hit-by-beacon-crm-data-breach-d6d5f2","The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek.","UK-based CRM provider Beacon has disclosed a data breach affecting over 1,000 charities. The incident, which occurred between July 27-28, involved hackers downloading encrypted customer database backups. The root cause is believed to be a compromised AWS access key exposed in public JavaScript build artifacts, allowing attackers to exfiltrate all data from the database. While sensitive financial information was not compromised, personal details like names, phone numbers, and email addresses may have been exposed.","Beacon CRM data breach exposes over 1,000 charities' donor and supporter information.","UK-based customer relationship management (CRM) provider Beacon revealed this week the likely root cause of a recent data breach affecting many organizations. Beacon’s CRM platform is designed for charities and other non-profit organizations to manage donors, supporters, volunteers, and related fundraising and service activities. The company revealed in early August that it had suffered a data breach in which hackers downloaded customer database backups. The data was encrypted, but Beacon admitted that the attackers could have decrypted it prior to exfiltration. In an update shared this week, Beacon reported that the earliest malicious activity was observed on July 27 and the hackers likely transferred the data on July 27-28. “Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs,” the company noted. “However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database.” Beacon’s investigation found that the threat actor obtained the data from an AWS environment by using a compromised AWS access key that may have been exposed in publicly available JavaScript build artifacts.Advertisement. Scroll to continue reading. Several of the affected UK charities have issued their own statements on the matter, with some revealing that the incident affects all of Beacon’s more than 1,000 customers. Some charities said personal information belonging to supporters may have been compromised, including names, phone numbers, email addresses, and postal addresses. Others pointed out that no bank account numbers, sort codes, card numbers, or card security details have been exposed, as they do not store such sensitive financial information. The UK government’s Charity Commission is monitoring the situation and has issued guidance for affected organizations. No known cybercrime group appears to have taken credit for the attack on Beacon. The company says it’s not aware of the stolen data being published. Related: Ceva Logistics Operations Disrupted by Cyberattack Related: 3.8 Million Impacted by Unlimited Technology Systems Data Breach Related: Corporate Data Stolen in Levi Strauss Cyberattack Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs White House Mobilizes Security Firms for Operations Against Foreign Cybercrime GangsSharePoint Vulnerability Exploited Shortly After PoC ReleaseWhatsApp Unveils New Scam Alert FeatureChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities CombinedICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix ContactCisco Patches Firewall Zero-Day Exploited for DoS AttacksUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities Latest News 14,000 Trezor Customers Impacted by Data Breach at ShipMonkHackers Exploiting Unpatched GeoServer Zero-DayAmnesiaStealer macOS Malware Steals Data, Controls Browser SessionsCybersecurity M&A Roundup: 21 Deals Announced in July 2026Adobe Commerce Bug Targeted Immediately After DisclosureWordPress 7.0.4 Patches Remote Code Execution VulnerabilityVenture Firm Team8 Secures Additional $365 MillionFortinet Patches Authentication Flaws in FortiWeb and FortiManager Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveErika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.John Opala has joined Ralph Lauren as Chief Information Security Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fover-1000-charities-hit-by-beacon-crm-data-breach\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F07\u002Fdata-breach-healthcare-medical.jpg","2026-08-14T09:20:28+00:00","2026-08-14T10:00:21.124643+00:00",7,[18,21],{"name":19,"type":20},"Beacon","vendor",{"name":22,"type":23},"CRM","technology","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,35,37,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",[]]