Q: What exactly happened?
A: We recently experienced a cyber-security incident in which an unauthorised third party gained access to our systems. We acted quickly to identify the threat and contain it, and Beacon is operating normally.
Q: How did this happen?
A: Our understanding is that a compromised AWS (Amazon Web Services) access key was used to gain access to Beacon. This was more sophisticated than a simple compromised username and password. More technically, the probable root cause of this incident was a compromised AWS access key which was potentially exposed in public JavaScript build artifacts in the Beacon application.
Q: What data was accessed?
A: Analysis of Cost & Usage reports shows a significant increase in data transfer on 27–28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred. Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs. However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database. We have created a Security Incident Response Guide page to support you with next steps including understanding what and how you might need to inform your own contacts. Please visit that page at www.beaconcrm.org/incident-guidance.
Q: Was the data downloaded encrypted?
A: The data was encrypted at rest in AWS, but the threat actor had valid credentials and therefore downloads would have been decrypted by AWS and available unencrypted to the threat actor.
Q: Does this affect my account or the data I have shared with Beacon?
A: Our assessment is that the threat actor exported all data contained within the Beacon database, so all customers who were using Beacon before the 27th of August are affected. You should review the data potentially impacted and consider whether you need to notify your contacts. We have provided some step-by-step guides directly to customers on how to do this and shared template communications for your use, should you need to notify your contacts.
Q: Is Beacon still operational?
A: Yes, Beacon is fully operational and working as normal. Beyond our immediate containment actions, Beacon hasn’t experienced any service interruption as a result of this incident.
Q: Are my payments safe?
A: There is no evidence that any card details have been compromised, and you can safely continue to collect payments via Beacon forms, but you must follow the steps in the Security Incident Response Guide in order to update your payment providers and apps.
Q: When will you have more information?
A: It’s likely there are things we may never be able to find out about this incident. Also, there are some technical details that we won’t be able to share to protect our ongoing security position. We will provide all customers with a summary of the investigation findings once it has concluded in a few weeks, but the level of detail contained in this next and final update may not be any more than is contained in these FAQs.
Q: What else should I do in the meantime?
A: Firstly, as a precaution, we are prompting password resets for all users and we recommend you make it long and unique.
Our assessment is that the threat actor exported all data contained within the Beacon database, so we recommend that you progress with your analysis at this time to determine whether you need to notify any of your contacts. Please do make use of our Security Incident Response Guide (www.beaconcrm.org/incident-guidance) to support you.
Q: How can I be confident that Beacon takes security seriously?
A: Keeping your data secure is the most important thing we do at Beacon and we have significant measures in place to protect your data. We brought in expert third-party specialists as soon as we discovered this incident, and we are continuing to work with them to finalise our understanding of what happened and ensure it does not happen again. We have also reported the incident to the relevant authorities and regulators.
Q: Will this happen again?
A: Please know that we are taking this incident very seriously. Working with our expert third-party specialists, we are conducting a comprehensive investigation to understand more about what happened and to ensure we implement any additional safeguards needed to prevent this from happening again. Security is a continual process for us, and we are committed to keeping your data safe.
Q: What have you done to secure your systems/Are your systems secure now?
A: Having identified the probable root cause of this unauthorised access, we have remediated the vulnerability and reset all credentials for services and accounts integrated with Amazon Web Services (AWS). To ensure the continued security of our systems we have deployed SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) across our environment and engineer endpoints. These security software solutions continuously scan our environment for Indicators of Compromise and suspicious activity. Alerts from these solutions are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Through this monitoring, our external cyber security experts have been able to confirm that, since containing the initial incident, they have not identified or observed any ongoing unauthorised access to Beacon's AWS environment or engineer endpoints.
Q: I have a question that is not answered here. Who should I contact?
A: Please read our dedicated Security Incident Response Guide web pages at www.beaconcrm.org/incident-guidance, which have step-by-step guides, FAQs and template documents. If you have further questions that can’t be answered using the webpages then please do get in touch via our in-app messaging as you normally would or by emailing us at incident@beaconcrm.org. Our team will be here to help. We will come back to you as soon as possible, but please bear with us as volume may mean we are slower to respond in the short term.
Q: I am concerned about the security of my data and have questions that you haven’t addressed. What should I do?
A: Please contact our support team and let us know your concerns. We are here to help and will be happy to discuss this with you.
12th of August 2026 at 17:01: FAQs updated to reflect the latest incident update.
5th of August 2026 at 17:45: FAQ updated: How did this happen?
4th of August 2026 at 17:56: FAQ added: Q: What have you done to secure your systems/Are your systems secure now?
4th of August 2026 at 13:05: FAQ updated: What data was accessed?