Beacon CRM Data Breach Exposes Personal Data of Over 1,000 UK Charities in AWS Credential Compromise

Beacon CRM Data Breach Exposes Personal Data of Over 1,000 UK Charities in AWS Credential Compromise

Executive Summary

On July 27, 2026, a data breach at Beacon CRM exposed the personal information of supporters and donors from over 1,000 UK charities, including organizations in healthcare and victim support sectors. The breach was caused by a compromised AWS access key that was inadvertently exposed in public JavaScript build artifacts, allowing an unauthorized actor to access and exfiltrate the full customer database and attachments. The incident lasted approximately 1 hour and 27 minutes, during which a significant spike in data transfers was observed. The compromised data included names, email addresses, phone numbers, donation records, and attachments, but did not include payment card, bank account, or patient data. The breach was detected on July 29, 2026, and publicly disclosed by Beacon on August 4, 2026. Immediate remediation steps included credential rotation, removal of exposed secrets, and deployment of additional security tooling. Regulatory authorities, including the UK Information Commissioner’s Office (ICO), were notified, and affected charities began warning their supporters. No specific threat actor has been attributed, and no evidence of data being published on the dark web has been reported as of the latest updates. All technical findings and claims in this report are corroborated by primary sources, including Infosecurity Magazine (7 August 2026) and Mallory.ai (first seen August 13, 2026).

Technical Information

The breach at Beacon CRM was initiated through the exploitation of a compromised AWS access key, which was exposed in publicly accessible JavaScript build artifacts. This exposure allowed an attacker to authenticate directly to AWS services with valid credentials, bypassing traditional perimeter defenses and encryption at rest. The attacker’s access began at 01:20:16 UTC on July 27, 2026, and lasted for approximately 1 hour and 27 minutes. During this window, a sharp increase in AWS data transfers was observed, consistent with the exfiltration of the entire customer database and associated attachments.

The compromised data included personally identifiable information (PII) such as names, email addresses, telephone numbers, donation records, and file attachments. Beacon confirmed that no payment card, bank account, or patient data was stored in the affected environment. Although the data was encrypted at rest, the use of valid credentials allowed the attacker to download the information in a readable format.

No malware, persistence mechanisms, or post-exploitation tools were identified during the investigation. The breach was contained with the assistance of external cybersecurity experts, and no ongoing unauthorized access has been detected since the initial incident. Beacon responded by rotating all AWS-integrated credentials, removing sensitive build parameters from client-side JavaScript, and deploying additional security tooling, including endpoint detection and SentinelOne Cloud Native Security.

The attack method aligns with several MITRE ATT&CK techniques: T1552.001 (Unsecured Credentials: Credentials in Files), T1078 (Valid Accounts), T1530 (Data from Cloud Storage Object), and T1041 (Exfiltration Over C2 Channel). The root cause and technical sequence of events are supported by direct statements from Beacon and forensic analysis reported by both Infosecurity Magazine and Mallory.ai.

No specific threat actor has been attributed to the breach. The method of credential exposure in public code artifacts is consistent with tactics used by both financially motivated cybercriminals and state-affiliated actors in previous incidents, such as the Snowflake customer breaches in 2024. However, no data from this breach has appeared on dark web leak sites, and there is no evidence of extortion or ransom demands as of the latest reporting.

The breach primarily impacted charities and non-profits, particularly those in healthcare, victim support, and social services. Named affected organizations include Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice, The Survivor’s Trust, Justice for Colombia, Center for Sustainable Energy, British Deaf Association, and Yorkshire's Brain Tumour Charity. The incident highlights the risks associated with third-party platform dependency and the significant reputational stakes for organizations whose operations rely on donor trust.

Affected Versions & Timeline

The breach affected all Beacon CRM customers whose data was stored in the platform as of July 27, 2026. The attack window began at 01:20:16 UTC on July 27, 2026, and lasted for approximately 1 hour and 27 minutes. Beacon detected the incident on July 29, 2026, and began notifying affected customers on August 3, 2026. Public disclosure occurred on August 4, 2026, with further details released by the company’s CTO on August 12, 2026. The UK Information Commissioner’s Office (ICO) cleared The Survivor’s Trust of responsibility for the breach on August 13, 2026.

Threat Activity

The attacker exploited a compromised AWS access key exposed in public JavaScript build artifacts to authenticate to Beacon’s cloud environment. This allowed the attacker to export the full customer database and attachments within a short time frame, as evidenced by a significant spike in AWS data transfers. The attack did not involve malware, lateral movement, or privilege escalation, and no persistence mechanisms were identified. The breach was contained promptly, and no ongoing unauthorized access has been observed since the initial incident.

No specific threat actor has been attributed to the breach. The attack method is consistent with credential-based cloud data theft observed in previous incidents, such as the Snowflake breaches in 2024. The lack of data publication on dark web sites and absence of extortion attempts suggest that the attacker’s objectives remain unclear. The incident underscores the vulnerability of organizations relying on third-party platforms and the importance of securing credentials in software development pipelines.

Mitigation & Workarounds

The following mitigation steps were implemented by Beacon in response to the breach: all AWS-integrated credentials were rotated and revoked, sensitive build parameters were removed from client-side JavaScript, and additional security tooling, including endpoint detection and SentinelOne Cloud Native Security, was deployed. Affected organizations were advised to follow the steps outlined in the Beacon Security Incident Response Guide, update their payment providers and apps, and report the breach to the UK Information Commissioner’s Office (ICO).

For organizations using third-party platforms, it is critical to regularly audit and monitor for exposed credentials in public code repositories and build artifacts, enforce least-privilege access controls, and deploy robust cloud security monitoring solutions. Immediate notification of affected individuals and regulatory authorities is essential to comply with data protection requirements and maintain stakeholder trust.

Indicators of Compromise

The following indicators of compromise (IOCs) are extracted from public reporting as of August 13, 2026. These IOCs are point-in-time and should be validated before enforcement in production environments.

Type

Indicator

Reported (date)

Source

 

Domain

beaconcrm[.]org

2026-08-13

https://mallory.ai/stories/019ffbe5-5618-7c42-875b-4406160fb877

Domain

cybersecuritynews[.]com

2026-08-13

https://mallory.ai/stories/019ffbe5-5618-7c42-875b-4406160fb877

Domain

infosecurity-magazine[.]com

2026-08-13

https://mallory.ai/stories/019ffbe5-5618-7c42-875b-4406160fb877

Domain

lawcare[.]org[.]uk

2026-08-13

https://mallory.ai/stories/019ffbe5-5618-7c42-875b-4406160fb877

Domain

mallory[.]ai

2026-08-13

https://mallory.ai/stories/019ffbe5-5618-7c42-875b-4406160fb877

References

Infosecurity Magazine, 7 August 2026: https://www.infosecurity-magazine.com/news/healthcare-victim-charities-beacon/ Mallory.ai, first seen August 13, 2026: https://mallory.ai/stories/019ffbe5-5618-7c42-875b-4406160fb877

About Rescana

Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor risks associated with external vendors and service providers. Our platform enables continuous monitoring for credential exposures, supply chain vulnerabilities, and compliance gaps, supporting proactive risk mitigation and incident response. For questions about this report or to discuss how to strengthen your third-party risk management program, contact us at info@rescana.com.