Originally published at ictcrm.com
Short answer: the CRM software was not broken. In the biggest CRM breaches of 2026, attackers turned up holding a valid credential or an OAuth token nobody had revoked, then used ordinary product features to pull data out in bulk. No patch would have stopped any of it. Knowing what still holds a key to your system would have.
Beacon CRM is the one in the news this week. The London company runs a cloud CRM used by more than 1,000 charities for donations, memberships and event ticketing. It became aware of an incident on 29 July 2026 and notified its customers on 3 August. An unauthorised third party had used compromised login credentials to reach Beacon's systems and take copies of database backups. Beacon has told charities to assume that everything they stored, attachments included, may have been taken.
Four steps, none of which require a vulnerability in the product.
The same pattern shows up in every 2026 CRM software breach
Look a
Discussion
Be the first to comment
Add your perspective to get the discussion started.