Beacon, a UK-based customer relationship management platform used by charities and other non-profit organizations, has disclosed the likely root cause of a data breach that affected all of its more than 1,000 customers. The company first reported the incident in early August, revealing that attackers had downloaded encrypted backups of its customer database.
In an updated disclosure this week, Beacon said the earliest signs of malicious activity appeared on July 27, with the actual data transfer likely occurring between July 27 and July 28. Investigators determined that the attacker obtained access through a compromised AWS access key, which may have been exposed in publicly available JavaScript build artifacts.
Beacon said its logs could not definitively confirm which specific objects were accessed or where the exfiltrated data was sent. However, based on the volume of data transferred compared to the total size of the stored database, the company assessed that the threat actor likely exported the entire dataset.
Although the backups were encrypted, Beacon acknowledged that the attacker may have had the ability to decrypt the data before exfiltration, meaning the exposure could extend beyond raw ciphertext.
Impact on Charities and Supporters
Several affected charities have issued their own notifications confirming that the breach impacts all Beacon customers. Some organizations said supporter information, including names, phone numbers, email addresses, and postal addresses, may have been compromised. Others emphasized that no payment card numbers, bank account details, or sort codes were exposed, since that financial data is not stored within the platform.
The UK Charity Commission is monitoring the incident and has issued guidance to help affected organizations respond and communicate with their donors and supporters.
Attribution Still Unclear
No cybercrime group has claimed responsibility for the attack, and Beacon says it has no evidence that the stolen data has been published or offered for sale. The incident underscores the risk posed by hardcoded or exposed cloud credentials in client-side code, a recurring root cause in cloud-based data breaches affecting third-party service providers.
