UK-based customer relationship management (CRM) provider Beacon revealed this week the likely root cause of a recent data breach affecting many organizations.

Beacon’s CRM platform is designed for charities and other non-profit organizations to manage donors, supporters, volunteers, and related fundraising and service activities.

The company revealed in early August that it had suffered a data breach in which hackers downloaded customer database backups. The data was encrypted, but Beacon admitted that the attackers could have decrypted it prior to exfiltration.

In an update shared this week, Beacon reported that the earliest malicious activity was observed on July 27 and the hackers likely transferred the data on July 27-28.

“Specific objects, exact destination of the downloads, and definitive attribution of which objects were accessed cannot be determined from available logs,” the company noted. “However, having reviewed the data transfer volume and the total volume of data stored across the system, our assessment is that the threat actor exported all data contained within the database.”