Beacon CRM breach exposes data of 1,500 UK charities
A hacker broke into CRM provider Beacon using a stolen AWS access key that had been exposed in public JavaScript code. The attacker downloaded the entire customer database, exposing supporter data held by around 1,500 UK charities, including groups that support abuse survivors, refugees, and hospital patients. Beacon says it found no sign the stolen data has been published or misused so far.
- Started
- Jul 27, 2026
- Latest activity
- Sep 1, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United Kingdom
- Sectors
- Consumers
- Scale
- Beacon's entire customer base of about 1,500 UK charities
Current status
No credible reporting or official incident statement dated after 2026-09-01 was found as of 2026-09-09.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Impact
Attacker downloaded Beacon's full CRM database, exposing charity supporters' names, email addresses, phone numbers and donation records; no payment card or sensitive patient data was stored in the system. Newly confirmed affected organizations include the Scottish Refugee Council, the Scottish Women's Institutes, the Cyrenians, the Environmental Rights Centre for Scotland, a Manchester HIV charity, Sheffield Hospitals Charity, and the English National Ballet.
What to do
If you have supported a UK charity, watch for phishing or social-engineering emails referencing your donation history and report any suspicious contact to the charity involved.
Timeline
-
Sep 1, 2026
Silicon UK reported additional confirmed victims of the Beacon breach, including the Scottish Refugee Council, the Scottish Women's Institutes, the Cyrenians, the Environmental Rights Centre for Scotland, a Manchester HIV charity, Sheffield Hospitals Charity and the English National Ballet; Beacon said it had contained the breach and improved its security.
Containedsilicon.co.uk -
Aug 29, 2026
The Robert Burns Ellisland Trust in Dumfries told supporters their contact and donation details may have been accessed, one of several Scottish charities, including the Scottish Refugee Council and the Scottish Council for Voluntary Organisations, still notifying members about the Beacon breach weeks later.
Containednews.stv.tv -
Aug 13, 2026
Affected charity The Survivor's Trust said the UK Information Commissioner's Office had reviewed its case and found the charity not responsible for the breach.
Containedinfosecurity-magazine.com -
Aug 12, 2026
Beacon issued an incident update naming an exposed AWS key in public JavaScript build artifacts as the likely root cause.
Containedinfosecurity-magazine.com -
Jul 27, 2026
Attacker used a compromised AWS access key to access and download Beacon's full CRM database over about 90 minutes.
Activeinfosecurity-magazine.com
Sources
- Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities Infosecurity Magazine Aug 13, 2026
- Over 1,000 Charities Hit by Beacon CRM Data Breach SecurityWeek Aug 14, 2026
- AWS key exposed in JavaScript may have lit way to Beacon's charity data The Register Aug 13, 2026
- Robert Burns charity urges members to be vigilant after major cyberhack STV News Aug 29, 2026
- Robert Burns Charity Hacked In Beacon CRM Breach Silicon UK Sep 1, 2026
Related reports
- Beacon CRM charity data breach Aug 14, 2026
- UK charities' data leaked via Beacon's AWS mistake Aug 13, 2026