Beacon CRM AWS Key Leak Exposes Full Donor Databases of 1000+ UK Charities
Beacon CRM suffered a full database exfiltration via a leaked AWS key in public JavaScript, impacting over 1,000 charities' donor records. The breach highlights systemic weaknesses in cloud configuration and third-party risk management for the non-profit sector. Donor confidence and regulatory compliance face measurable short-term damage.
Beacon confirmed the earliest malicious activity on July 27 with data transfer completing the next day. Logs could not pinpoint exact objects accessed, but volume analysis showed the threat actor exported the entire database contents. The root cause was an exposed AWS access key in publicly available build artifacts, a configuration error that granted broad S3 and RDS read permissions without additional controls.
The incident follows a documented pattern of credential leakage through client-side artifacts in cloud-hosted SaaS platforms serving regulated sectors. Unlike prior incidents where partial datasets were recovered, Beacon assessed complete export occurred. No payment card or bank details were present, yet names, addresses, emails, and supporter relationship records were exposed, directly undermining donor trust mechanisms that charities rely on for recurring revenue.
Charity Commission monitoring and individual charity disclosures reveal inconsistent incident response capabilities across the sector. Several organizations lacked encryption at rest for backups or monitoring for anomalous key usage, amplifying downstream risk. This exposure is likely to accelerate regulatory scrutiny on third-party CRM providers handling personal data under UK GDPR.
Affected charities must now issue breach notifications and implement enhanced key rotation and artifact scanning within 30 days. Independent audits of similar non-profit SaaS vendors are expected to identify comparable misconfigurations before additional incidents surface.
Charity Commission: at least 150 affected organizations will report formal donor opt-out spikes exceeding 12% within 90 days of notification
Sources (3)
- [1]Primary Source(https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/)
- [2]Supporting Source(https://www.gov.uk/government/publications/charity-commission-guidance-on-data-breaches)
- [3]Supporting Source(https://aws.amazon.com/security/security-bulletins/)