UK-based customer relationship management (CRM) provider Beacon revealed this week the likely root cause of a recent data breach affecting many organisations.
Beacon’s CRM platform is designed for charities and other non-profit organizations to manage donors, supporters, volunteers and related fundraising activities and services.
The company disclosed in early August that it had suffered a data breach in which hackers downloaded backup copies of a customer database. The data was encrypted, but Beacon acknowledged that the attackers may have decrypted it before the exfiltration.
In an update shared this week, Beacon reported that the earliest malicious activity was observed on July 27 and the hackers likely transferred the data on July 27-28.
“The specific objects, the exact destination of the downloads, and the final attribution of which objects were accessed cannot be determined from the available logs,” the company notes. “However, after reviewing the volume of data transfer and the total volume of data stored on the system, it is our assessment that the threat exported all data contained in the database.”
Beacon’s investigation determined that the threat obtained the data from an AWS environment by using a compromised AWS access key that may have been disclosed in publicly available JavaScript build artifacts.
Several of the UK charities affected have issued their own statements on the matter, with some revealing that the incident affects all of Beacon’s more than 1,000 customers.
Some charities said personal information belonging to supporters may have been compromised, including names, phone numbers, email addresses and postal addresses.
others pointed out that no bank account numbers, sort codes, card numbers or card security details were disclosed as they do not store such sensitive financial information.
The UK Government’s Charity Commission is monitoring the situation and has issued guidance for the organizations concerned.
No known cybercrime group appears to have claimed responsibility for the Beacon attack. The company says it is not aware of the publication of the stolen data.
Connected: Ceva Logistics operations disrupted by cyber attack
Connected: 3.8 million affected by data breach in unrestricted technology systems
Connected: Corporate data stolen in Levi Strauss cyber attack