Beacon Security Incident

Page Navigation

This page tracks the information and actions undertaken in response to the Beacon security incident at the end of July 2026.

12 August 2026. Beacon Notification Update

I am writing to provide a further update on our investigation into the cyber-security incident we reported to you on Monday.

We have today received a further update from our external cyber security experts on the progress of their investigation which we wish to share with you.

This update confirms their assessment that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor.

Initial access and root cause

The probable root cause of this incident was a compromised AWS access key which was potentially exposed in public JavaScript build artifacts. The earliest malicious activity observed so far occurred on 27 July 2026 at 01:20:16 UTC and lasted for approximately 1 hour and 27 minutes.

Nothing in the ongoing forensic and threat intelligence investigations has identified evidence as to who the threat actor was.

Data exfiltration assessment

Analysis of the AWS Cost & Usage reports across May-July 2026 has been conducted. This data showed a significant increase in data transfer on 27–28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred. Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs. However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database.

The data was encrypted at rest in AWS, but the threat actor had valid credentials and therefore downloads would have been decrypted by AWS and available unencrypted to the threat actor.

There has been no indication from online monitoring that data associated with the incident has been published, disclosed or otherwise misused.

Persistence

No methods of persistence used by the threat actor to maintain access to the AWS environment have been identified.

Having identified the most likely root cause of the unauthorised access, the vulnerability has been remediated and all credentials for services and accounts integrated with AWS reset.

SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) have been deployed across the environment and engineer endpoints to continuously scan for Indicators of Compromise and suspicious activity. Any alerts are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Since containing the initial incident and remediating the likely root cause, no suspicious activity or ongoing unauthorised access to Beacon’s AWS environment or engineer endpoints has been identified.

I know that following this update you may have additional questions.

Whilst we are still awaiting the completion of the investigation, I would like to give you some guidance about what to expect next.

It’s likely there are things we may never be able to find out about this incident. Also, there are some technical details that we won’t be able to share to protect our ongoing security position. We will provide all customers with a summary of the investigation findings once it has concluded in a few weeks, but the level of detail contained in this next and final update may not be any more than the above. I recognise this is frustrating, but unfortunately it is the reality of complex incidents like this. With this in mind, we would recommend making your own risk assessments now regarding onward notification to impacted data subjects using your knowledge of the data you process and store with Beacon. Whilst we can’t advise you on these risk assessments, as they will be unique to the data each customer stores, the team remains available via live chat and email ([email protected]) to help where we can, and we will be keeping our FAQ and Guide pages up to date.

I’d like to thank you for your understanding and patience as we’ve worked through this incident. Keeping your data secure is the most important thing we do at Beacon, and I recognise the serious impact this incident has had on your organisation. Sadly, these types of incidents are becoming more frequent here in the UK, and affect all types of businesses.

Having quickly contained the incident, we have worked with external cyber security specialists to further enhance the comprehensive security measures we already had in place. Longer term in the engineering team, we are committed to continuing to build and update our platform with the very latest cyber security threats front of mind as we look to become a leader in security in our space. We will not be complacent, and will continue to constantly review our security posture to ensure we are doing all we can to protect your data.

5 & 6 August 2026. Communication Matters Notifies All Contacts of Beacon Security Incident

We’re getting in touch to provide information about a cyber-security incident and what we are doing about it.

Last week, Beacon CRM, one of our service providers experienced a cyber-security incident. This involved unauthorised access to our Membership and Contact system, and is likely to include your personal data.

We have been advised that transaction and payment details have not been affected.

I’m so sorry to be sharing this news. We know this will be concerning, and we are taking it seriously.

We have reported this incident to the Information Commissioner’s Office, (reference number IC-547876-Q6B3).

Beacon CRM has also made its report to the ICO, (reference number IC-0238-2026).

If you have further questions that aren’t answered in this email, please visit our web page for full details of all that we know about this security incident.

All responses to this email will be directed to [email protected]. We will come back to you as soon as possible, but please bear with us as we anticipate an increase in enquiries.

4 August 2026. ICO Response to Communication Matters Confirming Case is Closed

Reference Number IC-547876-Q6B3

I am writing about the personal data breach report you submitted on 3 August 2026. Thank you for the information you have provided. 

Data security requirements  

You must have appropriate technical and organisational measures in place to protect personal information. The more sensitive the personal information you are handling, the stronger your security measures must be.

Our decision 

We are aware of an incident relating to Beacon CRM which has impacted multiple organisations. At this time, your report has been logged and we do not plan to contact you further. If we need further information from you we be will in touch in due course. 

Please note that we may make enquiries if we become aware of new information that affects the circumstances of this case, including if we receive complaints about the breach. 

In response to a personal data breach, you should:

• Take reasonable steps to contain the incident. This may include obtaining updates and acting upon guidance from the data processor.
• Consider any steps you can take to mitigate the impact and support the affected individuals.
• Check that your data sharing contracts, policies and procedures are fit for purpose and are being followed.

If you haven’t already done so, you should investigate the root cause of the incident. This can help you to identify any additional technical or cyber security measures that can be implemented to prevent a recurrence.

Further Information

We deal with thousands of personal data breach reports each year. In many cases, the breach could easily have been prevented. Please read the attached leaflet, which contains guidance for preventing the most common cyber security related personal data breaches.

The UK’s National Cyber Security Centre provides guidance and outlines steps you can take to mitigate cyber-attacks. If you’re not doing these things already, please consider implementing them. 

Please also note that as a result of a breach an organisation may experience a higher volume of complaints and information rights requests. If you receive complaints, these should be initially dealt with through your internal complaints procedures. You should not refer them to the ICO as a matter of course. Although if an individual is not happy with your response, they can raise a complaint with us.  

Thank you for reporting the breach. Further information and guidance relating to personal data breachesand data security is available on our website.

We now consider the matter to be closed. 

4 August 2026. Beacon Notification Update


​I am writing to provide a further update on our investigation into the cyber-security incident we reported to you on Monday.

We recognise it has been a frustrating time for our customers as we sought to get further detail on what happened and we apologise that a lot of your questions have gone unanswered. This is because we just didn’t have the information to give to you – indeed, we might never know some of the answers we seek.

We did not want to speculate before the findings had been sufficiently verified, but we recognise that the limited information available until now has been frustrating.

Having worked as quickly as possible with our external experts on this incident, we want to share a further update with you all.

As before, Please visit our updated FAQs page (www.beaconcrm.org/incident-faqs) for immediate questions you may have.

If you have further questions that can’t be answered using these webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at [email protected]. We will come back to you as soon as possible, but please bear with us as volume may mean slower responding times in the short term.

Update as of Tuesday 4th August 2026.

Data impact

Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party. We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems. It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded.

Data encryption

Whilst we store data in an encrypted state, our experts have advised us that based on the available evidence it is possible that the unauthorised third party responsible for this incident would have been able to decrypt it before copying it from our systems.

Containment measures and ongoing security of our systems

Having identified the probable root cause of this unauthorised access, we have remediated the vulnerability and reset all credentials for services and accounts integrated with Amazon Web Services (AWS). To ensure the continued security of our systems we have deployed SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) across our environment and engineer endpoints. These security software solutions continuously scan our environment for Indicators of Compromise and suspicious activity. Alerts from these solutions are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Through this monitoring, our external cyber security experts have been able to confirm that, since containing the initial incident, they have not identified or observed any ongoing unauthorised access to Beacon’s AWS environment or engineer endpoints.

Reporting

We have made a report to the ICO. Our case number is IC/0238/2026. We have also contacted the authorities via Report Fraud. Based on the information available, you should make an assessment of your own reporting obligations.

Media

We understand that there has been some media interest in this incident. We wanted to share with you the statement we will be issuing to journalists that enquire directly with Beacon. We will not be commenting on the incident in any further detail. If you need to align on media approach or have questions from journalists you wish to ask us about, please contact [email protected] and we’d be happy to help.

The statement for the media is as follows:

A Beacon spokesperson said:

“We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.”

“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”

3 August 2026. Communication Matters Report to Information Commissioner's Office (ICO)

Reference Number: IC-547876-Q6B3)

3 August 2026. Beacon Notification


​We’re getting in touch to provide information about a recent matter, and to outline the steps we’ve taken to address it.

Late last week, we unfortunately experienced a cyber-security incident that involved unauthorised access to Beacon’s systems. We wanted to let you know early on, even though our investigation is still underway, because the incident is likely to have affected the data you store in our CRM.

I’m so sorry to be sharing this news. We know this will be concerning, and we’re taking it seriously.

To understand the situation and its potential impact, we have been working with external cyber-security experts. We’ll keep you updated as we learn more, and we’ll be honest about what we know and what we don’t yet know.

This email sets out what we understand so far, actions we have taken, and guidance on actions you need to take.

Please read it carefully and visit our dedicated Security Incident Response Guide web page (www.beaconcrm.org/incident-guidance) for advice on what you need to do, and our FAQs page (www.beaconcrm.org/incident-faqs) for more information.

If you have further questions that can’t be answered using the webpages, please do get in touch via our in-app messaging as you normally would or by emailing us at [email protected]. Our team will be here to help. We will come back to you as soon as possible, but please bear with us as volume may mean slower responding times in the short term.

Sincerely,
David Simpson
Chief Technology Officer

What Happened

Late last week, we became aware that we may have experienced a cyber-security incident. We immediately engaged external cyber-security experts to help us investigate. Our current understanding is that compromised credentials were used to gain access to Beacon, and copies of our database backups were made. Whilst the exfiltration (copying or taking) of this data hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded.

You can be confident that Beacon is available for you to use as normal. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident.

What Action we are Taking

Please know that we’re taking this seriously. We implemented immediate measures and right now we’re:

  • Conducting a thorough forensic investigation with our external cyber-security specialists to understand exactly what’s happened;
  • Working with law enforcement and relevant regulators as required;
  • Conducting continued online monitoring of the dark web, as is standard practice in these kinds of incidents. So far, we haven’t seen any reference or data linked to this incident;
  • Completing precautionary security measures, such as prompting password and two-factor authentication resets. If you use a password or an authenticator app when logging in to Beacon, you will have been prompted to reset these.

What Happens Next

As our investigation progresses, we will update you with what we learn.

In the meantime, if you were storing data about people in your Beacon account, it is likely to have been downloaded and as such you need to evaluate whether you must in turn notify the people you store in Beacon. We have developed a web page with step-by-step guidance on what you should do next based on what we know of the incident and your role as data controller. Please find all that information at www.beaconcrm.org/incident-guidance.

You have placed your trust in us as your partner, and that responsibility matters to us. We are committed to supporting you through this as best we can.

Connecting with Us

Please read our Security Incident Response Guide (www.beaconcrm.org/incident-guidance) and FAQ (www.beaconcrm.org/incident-faq) web pages carefully to support you with next steps. If you have further questions that can’t be answered using the webpages, then please do get in touch via our in-app messaging as you normally would or by emailing us at [email protected].