"A copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor," wrote CTO David Simpson.
Beacon's update and the exposed AWS access key
In its first public update more than a week after disclosing the breach on 4 August, Beacon identified an AWS access key "potentially exposed in public JavaScript build artifacts" as the leading suspect in the intrusion. The company said that, while data at rest in AWS was encrypted, the compromised access key may have allowed the attacker to retrieve that data in readable form.
Timeline: activity on 27–28 July 2026 and attack duration
Beacon's root cause analysis places the start of malicious activity in the early hours of 27 July, consistent with its initial estimates. Analysis of AWS Cost & Usage reports for May through July 2026 showed a "significant increase in data transfer on 27-28 July 2026," which Beacon says correlates with the malicious activity and "supports an assessment that substantial downloads occurred." Beacon reported the malicious activity lasted one hour and 27 minutes, and said the attacker established no persistence mechanisms in its AWS environment.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScope: database copy and attachments, but logs cannot show which records left
Beacon confirmed that a copy of the database containing all customer data and attachments was made. At the same time, the company acknowledged limits in its logging: its logs "cannot reveal which specific records left its systems," meaning Beacon cannot state which customer records were exfiltrated even though a full database copy was created.
Who is affected: customers, named charities, and the Charity Commission
Beacon serves more than 1,500 customers; the company has not established how many had data taken. Since Beacon's initial disclosure, an increasing number of charities have publicly confirmed they are affected. Early confirmations included Molly Rose Foundation, Macmillan Cancer Support Jersey, and English National Ballet. Subsequent confirmations included Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral.
The Charity Commission said "a number of charities have submitted serious incident reports," and that the volume of reports is causing delays to responses. "We appreciate your patience and understanding as we prioritise instances of the greatest risk," the regulator said.
How technologists, affected charities, and regulators are responding
- Technologists and security teams: Beacon urged customers to assess likely exposure by reviewing the data they store in their CRM instances. Beacon also warned that "there are things we may never be able to find out about this incident," and that some investigative details will be withheld to protect its security posture.
- Affected charities and procurement leaders: Beacon recommended customers make their own risk assessments now regarding onward notification to impacted data subjects using their knowledge of the data they process and store with Beacon.
- Regulators (the Charity Commission): The Charity Commission is triaging serious incident reports and prioritising the instances it deems highest risk, which has led to response delays as reporting volumes have grown.
Next steps Beacon promised — and the limits of future detail
Beacon said it will provide customers with a summary when the investigation concludes "in a few weeks," but cautioned that "the level of detail contained in this next and final update may not be any more than" the information it published in this update. That restraint, Beacon said, is intended to preserve its security position even as it seeks to close the inquiry.
The concrete facts here are narrow but consequential: an exposed AWS access key found in public build artifacts is Beacon's leading suspect; repository and billing analyses point to substantial downloads on 27–28 July 2026; a full copy of the customer database and attachments was made and likely downloaded; and Beacon's logs cannot say which individual records left its systems. For more than 1,500 customers and the charities that rely on Beacon to hold donor and personal information, the immediate task is a pragmatic one Beacon has laid out — review your stored records, run your own risk assessments, and prepare notifications where appropriate — while waiting for Beacon's promised final summary.



