CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Beacon CRM Confirms Full Database Theft After AWS Access Key Breach

Cybersecurity News Archived Aug 13, 2026 ✓ Full text saved

Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a threat actor made a complete copy of and exfiltrated its customer database. The disclosure, released by Chief Technology Officer David Simpson on August 12, 2026, marks a major escalation from initial statements and […] The post Beacon CRM Confirms Full Database Theft After AWS Access Key Breach appeared first on Cyber Security News .

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Beacon CRM Confirms Full Database Theft After AWS Access Key Breach By Guru Baran August 13, 2026 Beacon CRM Confirms Full Database Theft After AWS Access Key Breach Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a threat actor made a complete copy of and exfiltrated its customer database. The disclosure, released by Chief Technology Officer David Simpson on August 12, 2026, marks a major escalation from initial statements and clarifies the full scale of the compromise. According to Beacon’s forensic investigation conducted alongside external cybersecurity specialists, the intrusion stemmed from a compromised Amazon Web Services (AWS) access key. The sensitive credential was exposed within publicly accessible JavaScript build artifacts hosted directly on the company’s website. This class of credential leak occurs when automated build tools inadvertently bake environment variables or secret keys into client-facing code, allowing anyone inspecting web assets through a browser to harvest them. Similar exposure vectors routinely fuel credential phishing campaigns and automated scanning pipelines targeting exposed cloud infrastructure. Beacon CRM Confirms Full Database Theft As detailed in the official incident report published by Beacon CRM, forensic analysts reviewed AWS Cost and Usage reports spanning May through July 2026, identifying a massive surge in data transfer on July 27 and 28, 2026: Initial Access: The earliest malicious activity was recorded on July 27, 2026, at 01:20:16 UTC. Intrusion Window: The attacker operated for approximately 1 hour and 27 minutes before access was closed. Exfiltration Volume: A drastic spike in data transfer matched the total volume of stored platform records, leading investigators to conclude the entire database and attachment files were exported. A critical aspect of the breach involves how cloud storage encryption functions under credential theft. Although Beacon maintained data encryption at rest within its AWS environment, the adversary authenticated using valid, stolen AWS access keys. Because AWS automatically decrypts data for authorized credential holders, storage-level encryption provided no protection once the key was compromised. Consequently, the exfiltrated database records and file attachments were downloaded in fully readable form. The rapid trade of such exposed secrets across stolen credential markets highlights why long-lived API keys represent a persistent cloud security risk. Investigators found no evidence that the threat actor established persistent backdoors or secondary footholds within the infrastructure. Following the incident, Beacon completed several remediation steps: Credentials Rotated: Revoked and rotated all AWS-integrated access keys and secrets. Exposure Mitigated: Stripped sensitive build parameters from client-side JavaScript assets. Enhanced Telemetry: Deployed endpoint detection tools alongside SentinelOne Cloud Native Security across all enterprise environments and engineer workstations. The breach has triggered regulatory involvement from the UK Charity Commission, the Information Commissioner’s Office (ICO), and Action Fraud. Downstream, impacted non-profits including Justice for Colombia and the Center for Sustainable Energy have begun notifying supporters that personal information and donation histories may have been exposed. Beacon confirmed that continuous dark web monitoring has revealed no evidence of the stolen database being sold, published, or held for ransom. The company advises impacted client organizations to independently evaluate their data notification obligations while a final investigative report is prepared.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now. Tags cyber security news data breach Copy URL Linkedin Twitter ReddIt Telegram Guru Baranhttps://cybersecuritynews.com Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security News Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks Cyber Security Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers Cyber Security News North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees Cyber Security News CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks Cyber Security News GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗