Beacon CRM Data Breach: AWS Key Exposes 1,000+ Organizations

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Reconnaissance

The attacker scanned publicly served browser files of the Beacon application for credentials.

T1596 – Search Open Technical Databases T1592 – Gather Victim Host Information
  • AWS access key apparently present in public JavaScript build artifacts
  • Anything delivered to the browser is retrievable by anyone
  • No software vulnerability, no CVE involved
PHASE 2/5 · Initial Access

Using the exposed, valid AWS access key, the attacker gained legitimate access to the cloud environment.

T1552 – Unsecured Credentials T1078.004 – Valid Accounts: Cloud Accounts
  • Compromised AWS access key as probable root cause
  • Access appeared to AWS as an authorized user
  • No zero-day exploit, no patch possible
PHASE 3/5 · Collection

The attacker accessed the entire database including all attachments, delivered decrypted by AWS.

T1530 – Data from Cloud Storage Object
  • Encryption at rest did not help – AWS delivers decrypted for a valid key
  • Suspected access to database backups and attachment files
  • Data categories: names, email/postal addresses, phone numbers, donation details
PHASE 4/5 · Exfiltration

Within roughly 1.5 hours a large-scale data transfer occurred, likely a full database export.

T1567 – Exfiltration Over Web Service T1537 – Transfer Data to Cloud Account
  • Earliest malicious activity on 2026-07-27 at 01:20:16 UTC, lasting approx. 1h 27min
  • AWS Cost & Usage Reports showed a notable data transfer spike on July 27/28
  • Exact destinations and objects no longer determinable from logs
PHASE 5/5 · Impact

Beacon assesses a full database export as likely; over 1,000 organizations are potentially affected.

  • More than 1,500 customers; BBC cites over 1,000 potentially affected organizations
  • No persistence mechanisms and no attribution found
  • As of Aug 12, no indication of data publication or misuse
Short & clear answers
Frequently asked questions about this incident
Am I affected by the Beacon CRM incident?
You are affected or potentially affected if you used a Beacon account (including free trial accounts) or sent personal data to a Beacon instance before 27 July 2026. Simply running your own website does not make you affected. Check your vendor and processing records for an existing Beacon account or CRM/website integration as of the cut-off date.
What data may have been exposed in the breach?
Beacon considers an export of the entire database, including all attachments, likely because of the very high volume of data transferred. Which specific objects were downloaded can no longer be determined from the available logs. Affected data categories may include names of supporters and donors, email and postal addresses, phone numbers, and details of donations, volunteering or events — depending on your own data held in Beacon.
What do I need to do right now?
Immediately reset the passwords of all Beacon users to long, unique values and revoke all old Beacon API keys to reissue them. Disconnect connected services such as Mailchimp, JustGiving, SendGrid or Zapier and reconnect them with new keys. Also start a data protection process with an incident log and involve your data protection officer and management.
Do I have to report the incident to the data protection authority?
As the controller, you generally must report to the supervisory authority within 72 hours of becoming aware if there is a risk to affected individuals. Where a high risk is likely, you must also inform the affected individuals without delay in clear and plain language. Even if no reporting obligation applies, the incident must be documented.
Is there a patch or update I need to install?
No. This is not a classic software vulnerability with a CVE number, but the misuse of a valid AWS access key that was apparently exposed in public JavaScript files. Beacon states it has fixed the cause and reset all affected credentials. Your task as a customer is to reset passwords, reissue API keys and carry out a data protection risk assessment.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.