HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Beacon CRM Breach Exposes Donor Data Across 1,000 UK Charities

Beacon CRM confirmed that attackers used stolen credentials to download full database backups, exposing donor contact information and donation histories for over 1,000 charities. The incident highlights the importance of SOC 2 access‑control monitoring and continuous audit evidence.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
databreachtoday.com

Beacon CRM Breach Exposes Donor Data Across 1,000 UK Charities

What Happened — Beacon CRM, a cloud‑based CRM platform used by more than 1,000 charities in the United Kingdom, confirmed that attackers leveraged compromised credentials to copy database backups. The exfiltration likely includes all stored records, from donor contact details to donation histories.

Why It Matters for Compliance & Audit Readiness

  • Credential misuse directly tests the SOC 2 CC6 access‑control criteria that require strong authentication, least‑privilege provisioning, and continuous monitoring of privileged accounts.
  • The incident underscores the need for auditable evidence that credential hygiene (MFA, rotation, revocation) is enforced and that backup access is tightly controlled.
  • Continuous‑compliance programs must be able to surface real‑time logs and attest to remediation steps as part of a defensible SOC 2 audit trail.

Who Is Affected — Non‑profit and charitable organizations (e.g., English National Ballet, Center for Sustainable Energy) that store donor information, membership data, and event‑ticketing records in Beacon CRM.

Recommended Actions

  • Map the breach to SOC 2 CC6.1 & CC6.2 controls (user access provisioning and privileged‑access monitoring).
  • Enforce MFA for all administrative accounts and rotate any credentials that may have been exposed.
  • Enable immutable logging of backup access and collect logs as audit evidence.
  • Conduct a post‑incident security checklist, update your incident‑response playbook, and verify any regulatory reporting obligations (e.g., UK GDPR).

Source: DataBreachToday

Technical Notes — Attack vector: stolen credentials used to access the Beacon CRM environment; data types exfiltrated include personal donor details, donation amounts, and attached files. No payment card data reported. Source: same as above

📰 Original Source
https://www.databreachtoday.com/beacon-crm-widely-used-by-charities-suffers-data-breach-a-32420

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →