2026 Beacon Data Security Incident
On August 3, 2026, Beacon, a Customer Relationship Management platform, notified its users that they had experienced a cyber-security incident. Beacon first became aware that they may have experienced a cybersecurity incident on July 27, 2026, and they immediately engaged external cybersecurity experts to help investigate and secure their systems.
This breach impacts the data collected and stored by potentially all of Beacon’s more than one thousand customers, including EPIC. The records maintained by EPIC in Beacon’s platform include certain limited contact information and contribution history related to our supporters. EPIC does not store any payment information (including payment card information or financial account numbers), social security numbers, dates of birth, or other sensitive information with Beacon (or otherwise).
The information in Beacon’s database is stored in an encrypted format, but available evidence, Beacon assessed that an unauthorized third party likely had access to and exfiltrated decrypted data.
What happened:
Beacon has determined that compromised credentials were used to gain access to its system, and copies of database backups were made. It appears that this was a malicious attack on Beacon’s system by an external threat actor, and it has potentially impacted the data of all of Beacon’s customers, which are charitable organizations and affiliates.
Beacon has assessed that exfiltration (copying or taking) of data likely occurred and that copies of data were likely downloaded by an unauthorized third party. Beacon reports there is currently no evidence that this data has been shared on the dark web and they have not received a ransom request.
Beacon has provided notice that they have implemented immediate measures to secure its systems and prevent any further unauthorized access. Following the incident, they are:
- Conducting a thorough forensic investigation with their external cybersecurity specialists to understand exactly what happened;
- Working with law enforcement and relevant regulators as required;
- Conducting online monitoring, as is standard practice in these kinds of incidents. So far, they say they haven’t seen anything suggesting the data has been posted anywhere;
- Completing precautionary security measures.
Beacon has further advised that it has taken containment measures and implemented ongoing security measures in their systems:
“Having identified the probable root cause of this unauthorised access, we have remediated the vulnerability and reset all credentials for services and accounts integrated with Amazon Web Services (AWS). To ensure the continued security of our systems we have deployed SentinelOne Endpoint Detection and Response (EDR) and Cloud Native Security (CNS) across our environment and engineer endpoints. These security software solutions continuously scan our environment for Indicators of Compromise and suspicious activity. Alerts from these solutions are being monitored 24/7 and any Indicators of Attack or Compromise identified will be removed automatically. Through this monitoring, our external cyber security experts have been able to confirm that, since containing the initial incident, they have not identified or observed any ongoing unauthorised access to Beacon’s AWS environment or engineer endpoints.“
How EPIC is impacted:
Beacon is one of the third party processing entities that EPIC uses to maintain our donor, event, and mail contact records. . As such, our database was impacted by this breach, and we are posting details about this incident publicly so that all of our supporters, members, and others can understand what happened and how we are responding.
EPIC takes the privacy and security of our supporters’ data seriously, and we are closely evaluating and monitoring this situation to ensure that everyone has the most current and accurate data available about what happened and about any future risks. We have minimized the amount of data that we store with external vendors like Beacon, which helps to limit the potential harmful impact when a breach like this occurs.
The database that EPIC manages through Beacon includes personal data from individual donors, members, event attendees, and campaign supporters. This database does not include any payment information (including credit card or financial account numbers), social security numbers, dates of birth, or other sensitive data. EPIC uses the Beacon system to store the following Personal Data Elements (though not all records include every element):
- Name
- Address
- Contribution history
What happens next?
EPIC will continue to monitor the information posted by Beacon. Based on the circumstances and limited data stored with Beacon, it appears this incident poses little risk to our supporters and members. However, we will continue to evaluate the incident as we learn more, and provide any significant updates on this page.
EPIC continues to use Beacon to manage its database, and we have reset our credentials as an added precaution. More information about our third party processors and other data practices is available here https://epic.org/about/privacy/.
What should you do?
We do not believe that any of EPIC’s supporters or members need to take immediate steps in response to this incident. However, we encourage everyone to take caution and avoid responding to any suspicious messages or inquiries that you receive via mail, email, or telephone. If you do receive any suspicious messages that reference or relate to EPIC, please forward them to our attention.
Please direct any inquiries or questions about this data security incident to EPIC at privacy-contact [at] epic [dot] org.
(last updated September 10, 2026)