Beacon CRM Breach Exposes Data of 1,000+ Charities via Stolen Login Credentials
London-based Beacon CRM, used by over 1,000 charities for donations and memberships, detected an unauthorised breach on 29 July 2026 and notified customers on 3 August. Attackers used compromised login credentials to access Beacon's systems and copy database backups, potentially exposing all stored data including attachments. The incident mirrors two other 2026 CRM breaches: a campaign dubbed UNC6395 that abused unrevoked OAuth tokens to query Salesforce data across 700-plus organisations, and a Klue breach involving a credential first issued in 2022 that had never been deactivated. Security analysts note that in all three cases the authentication systems functioned as designed, meaning no software vulnerability was exploited and no patch could have prevented the intrusions. Experts warn that unmonitored third-party integrations and long-lived credentials represent a systemic risk, particularly for smaller organisations like charities that lack dedicated security staff.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in