UK-based customer relationship management (CRM) provider Beacon revealed this week the likely root cause of a recent data breach affecting many organizations.
Beacon’s CRM platform is designed for charities and other non-profit organizations to manage donors, supporters, volunteers, and related fundraising and service activities.
The company revealed in early August that it had suffered a data breach in which hackers downloaded customer database backups. The data was encrypted, but Beacon admitted that the attackers could have decrypted it prior to exfiltration.
In an update shared this week, Beacon reported that the earliest malicious activity was observed on July 27 and the hackers likely transferred the data on July 27-28.
“Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs,” the company noted. “However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database.”
Beacon’s investigation found that the threat actor obtained the data from an AWS environment by using a compromised AWS access key that may have been exposed in publicly available JavaScript build artifacts.
Several of the affected UK charities have issued their own statements on the matter, with some revealing that the incident affects all of Beacon’s more than 1,000 customers.
Some charities said personal information belonging to supporters may have been compromised, including names, phone numbers, email addresses, and postal addresses.
Others pointed out that no bank account numbers, sort codes, card numbers, or card security details have been exposed, as they do not store such sensitive financial information.
The UK government’s Charity Commission is monitoring the situation and has issued guidance for affected organizations.
No known cybercrime group appears to have taken credit for the attack on Beacon. The company says it’s not aware of the stolen data being published.
Related: Ceva Logistics Operations Disrupted by Cyberattack
Related: 3.8 Million Impacted by Unlimited Technology Systems Data Breach


