Beacon CRM Breach Exposes Data from Over 1,000 Charities
A data breach at Beacon CRM, a platform widely used by charities to manage donor and supporter data, has reportedly affected more than 1,000 organisations. Investigators believe the root cause was a compromised AWS access key that had been exposed in publicly available JavaScript build files—essentially, sensitive credentials left visible in code that anyone could access online.
This type of exposure is a common but preventable mistake: developers sometimes embed cloud service keys directly into front-end code during the build process, not realising these keys can be extracted by anyone inspecting the website's files. Once attackers obtain such a key, they can potentially access backend systems and any data stored within them, including donor records, contact details, and other sensitive information.
While the full scope of the data accessed hasn't been detailed, the incident is a reminder that even software vendors serving non-profit and small business sectors can become high-value targets. Businesses using third-party CRM or SaaS platforms should ask their vendors about how they secure cloud credentials and whether they conduct regular code audits to catch this kind of exposure before it becomes a breach.