UK-BASED CRM provider Beacon reported a data breach affecting over 1,000 charities, with potential exposure of personal supporter information. Malicious activity was first observed on July 27, 2026, utilizing a compromised AWS access key. While attackers downloaded database backups, the data was encrypted, and it's unclear what specific information was accessed. Charities confirmed no financial data was compromised. The UK's Charity Commission is monitoring the event and providing guidance. As of now, no group has claimed responsibility, and it remains unknown if the data has been published.
UK Charity CRM Beacon Hit by Data Breach After AWS Key Compromise
CyberSIXT Evidence Panel
Primary Source
gov.uk
Article by CyberSIXT