Beacon CRM discloses that a data breach impacts 1,500 or more UK charities, with the incident linked to unauthorized access to its systems. Multiple outlets report that the likely root cause is a compromised AWS access key rather than a flaw in the charities’ own systems.

SecurityWeek and Infosecurity Magazine both state that the exposed key was associated with artifacts included in Beacon’s public web assets. SecurityWeek specifies that the key was exposed in publicly available JavaScript build artifacts, suggesting attackers could retrieve it and use it to reach or access backend services. Infosecurity Magazine describes the access key exposure as the likely root cause but does not add further technical detail beyond that linkage.

Together, the reporting frames the breach as an access-key exposure scenario affecting a large customer base of UK nonprofit organizations using Beacon CRM, with the public availability of build artifacts identified as a key factor in how the credentials were obtained.