Beacon, a UK-based customer relationship management (CRM) provider specializing in charities and non-profit organizations, disclosed details regarding a recent data breach. The company initially reported the incident in early August, stating that hackers downloaded customer database backups.
Beacon's investigation indicates that the earliest malicious activity occurred on July 27, with data likely transferred on July 27-28. While specific objects and destinations of downloads could not be definitively determined, the volume of data transferred suggests that the threat actor exported all data contained within the database. This impacts over 1,000 of Beacon's charity customers.
The company's findings suggest that the attackers gained access to the data from an AWS environment. This was achieved by using a compromised AWS access key, which may have been exposed in publicly available JavaScript build artifacts.
Affected UK charities have issued their own statements, confirming that personal information of supporters, including names, phone numbers, email addresses, and postal addresses, may have been compromised. However, charities noted that sensitive financial information such as bank account numbers or card details were not stored on the platform and therefore not exposed. The UK government's Charity Commission is monitoring the situation and has provided guidance to affected organizations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Beacon, a UK-based CRM provider for non-profits, reported that a data breach likely exposed the entire customer database of over 1,000 charities. Attackers accessed data via a compromised AWS access key, potentially exposing personal information of supporters.