Beacon CRM Database Theft Linked to Exposed AWS Key

Beacon CRM Database Theft Linked to Exposed AWS Key

First seen 14 Aug 2026, 03:22 UTC TheregisterCybersecuritynewswww.beaconcrm.org 81% similarity 69.0

Article Content

Browse articles
ThreatCluster

Beacon, a CRM provider for charities, confirmed a breach where a complete copy of its customer database was exfiltrated. The breach is linked to an AWS access key exposed in public JavaScript build artifacts. CTO David Simpson stated that the malicious activity occurred on July 27, 2026, with significant data transfer noted in AWS Cost & Usage reports. The database contained personal information and donation details of affected charities. Although the data was encrypted at rest, the compromised access key allowed the attacker to access it in readable form. Beacon has over 1,500 customers but has not disclosed how many were affected. The company is conducting an investigation and has advised customers to assess their data exposure. This incident marks a significant escalation from initial reports of the breach.

Key Points: • Beacon confirmed a complete database theft linked to an exposed AWS access key. • The breach occurred on July 27, 2026, with significant data transfer noted. • Affected data includes personal information and donation details of charities.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
Malicious activity detected
Beacon identified significant data transfer correlating with a breach, leading to the exfiltration of customer data.
Theregister
2026-08-04
Breach disclosed to customers
Beacon publicly acknowledged the breach, informing customers of potential data exposure.
Theregister
2026-08-12
Full database theft confirmed
CTO David Simpson confirmed that a complete copy of the customer database was made and exfiltrated.
Cybersecuritynews
2026-08-13
Update on investigation released
Beacon provided an update on the investigation, advising customers to assess their data exposure.
Theregister

Community

Browse all →