Contained Medium impact Data breach Checked 1d ago

Beacon CRM breach exposes data of 1,500 UK charities

A hacker broke into CRM provider Beacon using a stolen AWS access key that had been exposed in public JavaScript code. The attacker downloaded the entire customer database, exposing supporter data held by around 1,500 UK charities, including groups that support abuse survivors, refugees, and hospital patients. Beacon says it found no sign the stolen data has been published or misused so far.

Started
Jul 27, 2026
Latest activity
Sep 1, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United Kingdom
Sectors
Consumers
Scale
Beacon's entire customer base of about 1,500 UK charities

Current status

No credible reporting or official incident statement dated after 2026-09-01 was found as of 2026-09-09.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Attacker downloaded Beacon's full CRM database, exposing charity supporters' names, email addresses, phone numbers and donation records; no payment card or sensitive patient data was stored in the system. Newly confirmed affected organizations include the Scottish Refugee Council, the Scottish Women's Institutes, the Cyrenians, the Environmental Rights Centre for Scotland, a Manchester HIV charity, Sheffield Hospitals Charity, and the English National Ballet.

What to do

If you have supported a UK charity, watch for phishing or social-engineering emails referencing your donation history and report any suspicious contact to the charity involved.

Timeline

  1. Sep 1, 2026

    Silicon UK reported additional confirmed victims of the Beacon breach, including the Scottish Refugee Council, the Scottish Women's Institutes, the Cyrenians, the Environmental Rights Centre for Scotland, a Manchester HIV charity, Sheffield Hospitals Charity and the English National Ballet; Beacon said it had contained the breach and improved its security.

    Containedsilicon.co.uk
  2. Aug 29, 2026

    The Robert Burns Ellisland Trust in Dumfries told supporters their contact and donation details may have been accessed, one of several Scottish charities, including the Scottish Refugee Council and the Scottish Council for Voluntary Organisations, still notifying members about the Beacon breach weeks later.

    Containednews.stv.tv
  3. Aug 13, 2026

    Affected charity The Survivor's Trust said the UK Information Commissioner's Office had reviewed its case and found the charity not responsible for the breach.

    Containedinfosecurity-magazine.com
  4. Aug 12, 2026

    Beacon issued an incident update naming an exposed AWS key in public JavaScript build artifacts as the likely root cause.

    Containedinfosecurity-magazine.com
  5. Jul 27, 2026

    Attacker used a compromised AWS access key to access and download Beacon's full CRM database over about 90 minutes.

    Activeinfosecurity-magazine.com

Sources

Related reports