Aug 13, 2026
Policy

Beacon AWS key breach may have exposed charity CRM data

Beacon says an AWS key possibly exposed in public JavaScript is its leading breach theory, after a database copy was likely downloaded.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

Beacon AWS key breach may have exposed charity CRM data
Photo: The Register

Beacon says its Beacon AWS key breach investigation has identified an AWS access key that may have been exposed in publicly available JavaScript build artifacts as the leading explanation for a July intrusion. The charity CRM provider says the suspected access route remains unproven, but that an attacker made a copy of its database, including customer data and attachments, and likely downloaded it in readable form.

The distinction matters for more than 1,500 Beacon customers. Beacon has identified neither the particular records that left its systems nor how many customers had data taken. Its logs cannot answer the first question, according to the company.

Beacon CTO David Simpson said the company reviewed AWS Cost & Usage reports for May through July and found a significant jump in data transfer on July 27 and 28. The timing matched the malicious activity and supports Beacon's assessment that substantial downloads occurred, he said. Beacon disclosed the incident on August 4.

What does Beacon say happened in the AWS key breach?

Beacon's root-cause analysis places the start of the activity in the early hours of July 27. It says the intruder was active for one hour and 27 minutes and did not establish persistence mechanisms in AWS. The company says its data was encrypted while stored, but that the potentially compromised key could have let the intruder retrieve data in readable form.

An AWS access key does not confer a fixed level of access. AWS says a holder can take actions allowed by the policies attached to those credentials. Its published response guidance is to determine which resources an exposed credential can reach, then invalidate it; unintended access remains possible until that happens. The incident is also a reminder that enterprise security is a program, not a product, spanning access controls, monitoring and operational process rather than encryption alone.

Beacon has told customers to assess likely exposure from the data held in their own CRM instances and make their own decisions about notifying affected people. Simpson cautioned that some facts may remain unavailable when the investigation ends and said the next update could contain little additional detail.

Which charities have reported being affected?

Several organizations have publicly said they were affected, according to The Register's reporting on Beacon's update. They include the Molly Rose Foundation, Macmillan Cancer Support Jersey, English National Ballet, Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association and Lincoln Cathedral. The Charity Commission said multiple charities had filed serious-incident reports and that the volume was delaying its responses.

For technology operators, the immediate lesson is narrower than Beacon's unresolved forensic finding: public exposure of a cloud credential can give a third party whatever access its attached permissions allow. Whether that was the route into Beacon's environment remains an assessment by the company, not an independently validated conclusion.

This story draws on original reporting from The Register.

More from Policy

All Policy →