Security News

Beacon CRM Breach Exposes Data from Over 1,000 Charities

Security Week · 14 Aug 2026
Key Takeaway Ask your software vendors how they protect cloud access keys and whether they scan public-facing code for exposed credentials, since a single leaked key can compromise thousands of customer records.

A data breach at Beacon CRM, a platform widely used by charities to manage donor and supporter data, has reportedly affected more than 1,000 organisations. Investigators believe the root cause was a compromised AWS access key that had been exposed in publicly available JavaScript build files—essentially, sensitive credentials left visible in code that anyone could access online.

This type of exposure is a common but preventable mistake: developers sometimes embed cloud service keys directly into front-end code during the build process, not realising these keys can be extracted by anyone inspecting the website's files. Once attackers obtain such a key, they can potentially access backend systems and any data stored within them, including donor records, contact details, and other sensitive information.

While the full scope of the data accessed hasn't been detailed, the incident is a reminder that even software vendors serving non-profit and small business sectors can become high-value targets. Businesses using third-party CRM or SaaS platforms should ask their vendors about how they secure cloud credentials and whether they conduct regular code audits to catch this kind of exposure before it becomes a breach.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.