UK Charity Sector Hit by Major Cyberattack Targeting Beacon CRM
Over 1,000 UK charities, including high-profile organizations like the English National Ballet and the Molly Rose Foundation, have been impacted by a cyberattack on Beacon CRM, a healthcare-focused customer relationship management provider. The breach, which occurred between July 26 and July 31, exposed sensitive data belonging to donors, supporters, and beneficiaries, raising concerns over potential phishing and identity fraud risks.
The attack stemmed from human error an employee accidentally leaked an AWS cloud storage access key, which cybercriminals exploited to infiltrate Beacon CRM’s systems and exfiltrate data. While initial assessments suggest payment information was not compromised, the stolen data may include contact details, making affected individuals vulnerable to targeted phishing campaigns.
Beacon CRM has notified authorities, including the Information Commissioner’s Office (ICO), and is working to contain the breach. The incident underscores the growing cybersecurity threats faced by organizations relying on cloud infrastructure, particularly those handling large volumes of personal data. Investigations are ongoing to determine the full scope of the exposure and the number of individuals affected.
English National Ballet cybersecurity rating report: https://www.rankiteo.com/company/english-national-ballet
Beacon CRM cybersecurity rating report: https://www.rankiteo.com/company/beaconcrm
Molly Rose Foundation cybersecurity rating report: https://www.rankiteo.com/company/molly-rose-foundation
"id": "ENGBEAMOL1787214313",
"linkid": "english-national-ballet, beaconcrm, molly-rose-foundation",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Over 1,000 UK charities',
'industry': 'Healthcare/Non-Profit',
'location': 'UK',
'name': 'Beacon CRM',
'type': 'CRM Provider'},
{'industry': 'Arts/Non-Profit',
'location': 'UK',
'name': 'English National Ballet',
'type': 'Charity'},
{'industry': 'Non-Profit',
'location': 'UK',
'name': 'Molly Rose Foundation',
'type': 'Charity'}],
'attack_vector': 'Human Error (AWS cloud storage access key leak)',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personal data)',
'type_of_data_compromised': ['Contact details',
'Sensitive '
'donor/supporter/beneficiary '
'data']},
'date_detected': '2024-07-31',
'description': 'Over 1,000 UK charities, including high-profile organizations '
'like the English National Ballet and the Molly Rose '
'Foundation, have been impacted by a cyberattack on Beacon '
'CRM, a healthcare-focused customer relationship management '
'provider. The breach exposed sensitive data belonging to '
'donors, supporters, and beneficiaries, raising concerns over '
'potential phishing and identity fraud risks.',
'impact': {'brand_reputation_impact': 'Potential brand reputation damage due '
'to data exposure',
'data_compromised': 'Sensitive data of donors, supporters, and '
'beneficiaries',
'identity_theft_risk': 'High (potential phishing and identity '
'fraud risks)',
'payment_information_risk': 'Low (payment information not '
'compromised)',
'systems_affected': 'Beacon CRM systems'},
'initial_access_broker': {'entry_point': 'AWS cloud storage access key leak'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Growing cybersecurity threats for organizations relying '
'on cloud infrastructure, particularly those handling '
'large volumes of personal data. Importance of securing '
'access keys and preventing human error.',
'post_incident_analysis': {'root_causes': 'Human error (leaked AWS access '
'key)'},
'regulatory_compliance': {'regulatory_notifications': ['Information '
'Commissioner’s Office '
'(ICO)']},
'response': {'communication_strategy': 'Notifications to authorities and '
'affected entities',
'containment_measures': 'Ongoing containment efforts'},
'title': 'UK Charity Sector Hit by Major Cyberattack Targeting Beacon CRM',
'type': 'Data Breach',
'vulnerability_exploited': 'Exposed AWS cloud storage access key'}