Beacon CRM has confirmed that a threat actor likely downloaded a complete copy of its customer database after gaining access to its Amazon Web Services (AWS) environment using a compromised AWS access key.
In an incident update published on August 12, Beacon stated that the database contained all customer data stored on the platform, including attachment files.
External cybersecurity investigators assessed that the data was likely obtained in a readable, unencrypted format, even though it was encrypted at rest within AWS.
The probable root cause of the incident was an AWS access key that may have been exposed in publicly accessible JavaScript build artifacts. Such artifacts can unintentionally contain embedded credentials, API keys, configuration values, or source map data if secrets are not removed before deployment.
Beacon CRM Data Breach
Beacon reported that the earliest observed malicious activity began on July 27, 2026, at 01:20:16 UTC and lasted for approximately one hour and 27 minutes. Investigators have not identified the responsible actor, and no attribution has been made public.
Forensic analysis of AWS Cost and Usage reports from May through July revealed a substantial increase in data transfer on July 27 and 28. This elevated transfer volume coincided with the unauthorized activity, supporting Beacon’s assessment that significant data downloads occurred.
However, the company noted that available logging could not determine which specific objects were accessed, the destination of the downloads, or conclusively establish which records were copied.
Based on the transfer volume and the total data held across the platform, Beacon assessed that the attacker likely exported all data contained in the customer database.
“Although the data was encrypted at rest in AWS, the threat actor had valid credentials,” Beacon stated. Consequently, AWS would have decrypted the data during access or download operations, potentially enabling the actor to obtain the records in plaintext.
Beacon has not found any evidence that data linked to the breach has been published, sold, disclosed, or otherwise misused online. The company also reported finding no persistence mechanisms in the AWS environment, suggesting the intruder did not establish any means of retaining access after the initial compromise.
Beacon said it has remediated the suspected exposure path and reset credentials for AWS-integrated accounts and services. Additionally, the company deployed SentinelOne Endpoint Detection and Response and Cloud Native Security tooling across its cloud environment and engineering endpoints.
These security controls are designed to continuously detect indicators of compromise, suspicious endpoint behavior, and cloud-based attack activity. Beacon stated that alerts are monitored around the clock, and identified indicators of attack or compromise are subject to automatic remediation.
Since the incident was contained and the likely root cause addressed, Beacon reported that it has detected no further unauthorized access or suspicious activity in its AWS environment or on engineering systems.
The company advised customers to conduct their own risk assessments and determine whether affected individuals require notification, based on the personal or sensitive data each organization stored in Beacon CRM. Beacon expects to provide a final investigation summary within a few weeks.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world





