Around 1500 UK charities have had personal information exposed after a compromised AWS access key was the likely root cause of a cyber-attack on CRM provider Beacon, the company disclosed in an August 12 incident update.
How the AWS access key was exposed
Beacon traced the root cause to an AWS access key that "was potentially exposed in public Javascript build artifacts." The vendor framed that finding as indicative of an error made during software development: the key appearing in publicly accessible build outputs would have allowed anyone holding it to authenticate to Beacon's AWS environment. That authentication, in turn, is what Beacon assesses the attacker used to access and download data from its CRM platform.
What was taken and which charities are affected
Beacon has assessed that the attacker used valid credentials to access and download all data contained within the CRM platform, including attachment files, thereby impacting its entire 1,500-strong customer base of charitable organisations. The company said the compromised CRM system did not hold sensitive patient information, payment card details or bank account information.
A number of charities have publicly declared they were affected. Confirmed victims named in disclosures include The Survivor’s Trust, Shrewsbury and Telford Hospital Charity, the British Deaf Association and Yorkshire's Brain Tumour Charity. Last week, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, homelessness charity the Clock Tower Sanctuary and Victim Support made similar announcements.
The types of supporter data thought to have been affected include names, email addresses, telephone numbers and donation records. Beacon also noted that some charities operating in highly sensitive areas—specifically healthcare and victim support—had personal information exposed, a detail that prompted at least one affected charity to advise supporters to remain vigilant for scams.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTimeline of the attacker’s activity
Beacon’s analysis of AWS Cost & Usage reports identified malicious activity beginning on July 27 at 01:20:16 UTC and lasting for approximately one hour and 27 minutes. The company said that timing correlates with a significant increase in data downloads on July 27 to 28, consistent with files being accessed and exfiltrated during that window.
Beacon’s defensive actions and current status
Beacon said that, while the data was encrypted at rest in AWS, the threat actor’s valid credentials meant its downloads would have been decrypted by AWS and available in readable form. Following discovery, the vendor reported it had reset all credentials for services and accounts integrated with AWS to prevent repeat unauthorized access. Beacon also stated it has not detected any attempts by the attacker to maintain persistence within its environment.
As of the company update, there has been no indication that the threat actor has published the stolen data online or otherwise misused it. Beacon has advised its charity customers to report the breach to the UK’s Information Commissioner’s Office (ICO).
What this means for charities, donors, and the ICO
- Charities: Beacon advised its charity customers to inform the ICO; The Survivor’s Trust reported that the ICO reviewed its case and concluded the charity holds no responsibility for the breach. Charities named in the incident statements are publicly urging supporters to be alert to potential scams.
- Donors and supporters: With names, emails, phone numbers and donation histories exposed, supporters face elevated risk of targeted social engineering; affected charities have warned their communities to watch for fraudulent contact in the coming weeks.
- The ICO and reporting obligations: Beacon’s guidance to report to the ICO places the regulator centrally in the incident response process; the ICO’s early review of The Survivor’s Trust was cited by that charity as clearing it of responsibility for the breach.
The facts now on the record show a short, focused window of compromise rooted in exposed developer artifacts and a valid cloud credential. Beacon has locked down credentials and reported the incident, and the ICO has begun reviewing at least some affected charities. What remains unresolved is whether the downloaded records will appear publicly or be repurposed for fraud—an outcome the company says has not been detected to date.
https://www.infosecurity-magazine.com/news/exposed-aws-key-data-charities/



