Theregister
Beacon CRM Database Theft Linked to Exposed AWS Key
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Beacon, a CRM provider for charities, confirmed a breach where a complete copy of its customer database was exfiltrated. The breach is linked to an AWS access key exposed in public JavaScript build artifacts. CTO David Simpson stated that the malicious activity occurred on July 27, 2026, with significant data transfer noted in AWS Cost & Usage reports. The database contained personal information and donation details of affected charities. Although the data was encrypted at rest, the compromised access key allowed the attacker to access it in readable form. Beacon has over 1,500 customers but has not disclosed how many were affected. The company is conducting an investigation and has advised customers to assess their data exposure. This incident marks a significant escalation from initial reports of the breach.
Key Points: • Beacon confirmed a complete database theft linked to an exposed AWS access key. • The breach occurred on July 27, 2026, with significant data transfer noted. • Affected data includes personal information and donation details of charities.