Beacon recently experienced a cyber-security incident that affected our systems. We want to keep you informed about what happened, what we are doing about it, and what this means for you.
We will be updating this page with relevant new information as our investigation progresses.
Dear Beacon customer,
We have today received a further update from our external cyber security experts on the progress of their investigation which we wish to share with you.
This update confirms their assessment that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor.
The probable root cause of this incident was a compromised AWS access key which was potentially exposed in public JavaScript build artifacts. The earliest malicious activity observed so far occurred on 27 July 2026 at 01:20:16 UTC and lasted for approximately 1 hour and 27 minutes.
Nothing in the ongoing forensic and threat intelligence investigations has identified evidence as to who the threat actor was.
Analysis of the AWS Cost & Usage reports across May-July 2026 has been conducted. This data showed a significant increase in data transfer on 27–28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred. Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs. However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database.
The data was encrypted at rest in AWS, but the threat actor had valid credentials and therefore downloads would have been decrypted by AWS and available unencrypted to the threat actor.
There has been no indication from online monitoring that data associated with the incident has been published, disclosed or otherwise misused.
No methods of persistence used by the threat actor to maintain access to the AWS environment have been identified.
Having identified the most likely root cause of the unauthorised access, the vulnerability has been remediated and all credentials for services and accounts integrated with AWS reset.
SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) have been deployed across the environment and engineer endpoints to continuously scan for Indicators of Compromise and suspicious activity. Any alerts are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Since containing the initial incident and remediating the likely root cause, no suspicious activity or ongoing unauthorised access to Beacon's AWS environment or engineer endpoints has been identified.
I know that following this update you may have additional questions.
Whilst we are still awaiting the completion of the investigation, I would like to give you some guidance about what to expect next.
It’s likely there are things we may never be able to find out about this incident. Also, there are some technical details that we won’t be able to share to protect our ongoing security position. We will provide all customers with a summary of the investigation findings once it has concluded in a few weeks, but the level of detail contained in this next and final update may not be any more than the above. I recognise this is frustrating, but unfortunately it is the reality of complex incidents like this. With this in mind, we would recommend making your own risk assessments now regarding onward notification to impacted data subjects using your knowledge of the data you process and store with Beacon. Whilst we can’t advise you on these risk assessments, as they will be unique to the data each customer stores, the team remains available via live chat and email (incident@beaconcrm.org) to help where we can, and we will be keeping our FAQ and Guide pages up to date.
I’d like to thank you for your understanding and patience as we’ve worked through this incident. Keeping your data secure is the most important thing we do at Beacon, and I recognise the serious impact this incident has had on your organisation. Sadly, these types of incidents are becoming more frequent here in the UK, and affect all types of businesses.
Having quickly contained the incident, we have worked with external cyber security specialists to further enhance the comprehensive security measures we already had in place. Longer term in the engineering team, we are committed to continuing to build and update our platform with the very latest cyber security threats front of mind as we look to become a leader in security in our space. We will not be complacent, and will continue to constantly review our security posture to ensure we are doing all we can to protect your data.
David Simpson
Chief Technology Officer
Beacon
All,
We recognise it has been a frustrating time for our customers as we sought to get further detail on what happened and we apologise that a lot of your questions have gone unanswered. This is because we just didn’t have the information to give to you - indeed, we might never know some of the answers we seek.
We did not want to speculate before the findings had been sufficiently verified, but we recognise that the limited information available until now has been frustrating.
We greatly appreciate all the patience you have shown us so far. We know this can’t have been easy.
Having worked as quickly as possible with our external experts on this incident, we want to share a further update with you all.
As before, Please visit our updated FAQs page (www.beaconcrm.org/incident-faqs) for immediate questions you may have.
If you have further questions that can’t be answered using these webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at incident@beaconcrm.org. We will come back to you as soon as possible, but please bear with us as volume may mean slower responding times in the short term.
Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party. We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems. It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded.
Whilst we store data in an encrypted state, our experts have advised us that based on the available evidence it is possible that the unauthorised third party responsible for this incident would have been able to decrypt it before copying it from our systems.
Having identified the probable root cause of this unauthorised access, we have remediated the vulnerability and reset all credentials for services and accounts integrated with Amazon Web Services (AWS). To ensure the continued security of our systems we have deployed SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) across our environment and engineer endpoints. These security software solutions continuously scan our environment for Indicators of Compromise and suspicious activity. Alerts from these solutions are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Through this monitoring, our external cyber security experts have been able to confirm that, since containing the initial incident, they have not identified or observed any ongoing unauthorised access to Beacon's AWS environment or engineer endpoints.
We have made a report to the ICO. Our case number is IC/0238/2026. We have also contacted the authorities via Report Fraud. Based on the information available, you should make an assessment of your own reporting obligations.
We understand that there has been some media interest in this incident. We wanted to share with you the statement we will be issuing to journalists that enquire directly with Beacon. We will not be commenting on the incident in any further detail. If you need to align on media approach or have questions from journalists you wish to ask us about, please contact press@beaconcrm.org and we’d be happy to help.
A Beacon spokesperson said:
“We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.
“We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact. Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal.”
David Simpson
Chief Technology Officer
Beacon
Late last week, we discovered that an unauthorised third party had gained access to our systems. We immediately took action to contain this and brought in expert cyber-security support.
We’re treating this seriously. We’ve implemented immediate measures, including:
- Conducting a thorough forensic investigation with our external cyber-security specialists to understand exactly what’s happened;
- Working with law enforcement and relevant regulators as required;
- Conducting continued online monitoring of the dark web, as is standard practice in these kinds of incidents. So far, we haven’t seen any reference or data linked to this incident.
Our current understanding is that compromised credentials were used to gain access to Beacon, and copies of database backups were made. Whilst the exfiltration (copying or taking) of that data hasn’t yet been confirmed, the evidence we have so far suggests these copies were likely downloaded.
You have placed your trust in us as your partner, and that responsibility matters to us. We are committed to supporting you through this as best we can.
As our investigation progresses, we will update you with what we’ve learned.
If you were storing data about people in your Beacon account, it is likely to have been downloaded and as such you need to evaluate whether you must in turn notify the people you store in Beacon. Please visit our Security Incident Response Guide (www.beaconcrm.org/incident-guidance) for our step-by-step guidance on what to do next.
Please visit our FAQs page (www.beaconcrm.org/incident-faqs) for immediate questions you may have.
If you have further questions that can’t be answered using these webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at incident@beaconcrm.org. We will come back to you as soon as possible, but please bear with us as volume may mean slower responding times in the short term.
Thank you for your patience and understanding.
David Simpson
Chief Technology Officer
Beacon