CyberSecurityNews

Beacon CRM Confirms Full Database Theft After AWS Access Key Breach


Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a threat actor made a complete copy of and exfiltrated its customer database.

The disclosure, released by Chief Technology Officer David Simpson on August 12, 2026, marks a major escalation from initial statements and clarifies the full scale of the compromise.

According to Beacon’s forensic investigation conducted alongside external cybersecurity specialists, the intrusion stemmed from a compromised Amazon Web Services (AWS) access key.

The sensitive credential was exposed within publicly accessible JavaScript build artifacts hosted directly on the company’s website.

This class of credential leak occurs when automated build tools inadvertently bake environment variables or secret keys into client-facing code, allowing anyone inspecting web assets through a browser to harvest them.

Similar exposure vectors routinely fuel credential phishing campaigns and automated scanning pipelines targeting exposed cloud infrastructure.

Beacon CRM Confirms Full Database Theft

As detailed in the official incident report published by Beacon CRM, forensic analysts reviewed AWS Cost and Usage reports spanning May through July 2026, identifying a massive surge in data transfer on July 27 and 28, 2026:

  • Initial Access: The earliest malicious activity was recorded on July 27, 2026, at 01:20:16 UTC.
  • Intrusion Window: The attacker operated for approximately 1 hour and 27 minutes before access was closed.
  • Exfiltration Volume: A drastic spike in data transfer matched the total volume of stored platform records, leading investigators to conclude the entire database and attachment files were exported.

A critical aspect of the breach involves how cloud storage encryption functions under credential theft. Although Beacon maintained data encryption at rest within its AWS environment, the adversary authenticated using valid, stolen AWS access keys.

Because AWS automatically decrypts data for authorized credential holders, storage-level encryption provided no protection once the key was compromised. Consequently, the exfiltrated database records and file attachments were downloaded in fully readable form.

The rapid trade of such exposed secrets across stolen credential markets highlights why long-lived API keys represent a persistent cloud security risk.

Investigators found no evidence that the threat actor established persistent backdoors or secondary footholds within the infrastructure. Following the incident, Beacon completed several remediation steps:

  1. Credentials Rotated: Revoked and rotated all AWS-integrated access keys and secrets.
  2. Exposure Mitigated: Stripped sensitive build parameters from client-side JavaScript assets.
  3. Enhanced Telemetry: Deployed endpoint detection tools alongside SentinelOne Cloud Native Security across all enterprise environments and engineer workstations.

The breach has triggered regulatory involvement from the UK Charity Commission, the Information Commissioner’s Office (ICO), and Action Fraud.

Downstream, impacted non-profits including Justice for Colombia and the Center for Sustainable Energy have begun notifying supporters that personal information and donation histories may have been exposed.

Beacon confirmed that continuous dark web monitoring has revealed no evidence of the stolen database being sold, published, or held for ransom.

The company advises impacted client organizations to independently evaluate their data notification obligations while a final investigative report is prepared.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link