Cyber Incident Victim: Yorkshire's Brain Tumour Charity
Timeline
Summary
An exposed AWS access key allowed attackers to download all data from the CRM platform used by Beacon, affecting over 1,500 UK charities including Yorkshire's Brain Tumour Charity. The compromised data comprised supporters' names, email addresses, telephone numbers and donation records, while no patient health information, payment card details or bank account data were stored in the system.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A compromised AWS access key was identified as the likely root cause of the cyber‑attack on the CRM provider Beacon, with the key potentially exposed in public JavaScript build artifacts during software development. Using these valid credentials, the attacker accessed and downloaded all data contained within Beacon’s CRM platform, including attachment files, thereby affecting the provider’s entire customer base of approximately 1,500 UK charities. Analysis of Beacon’s AWS Cost & Usage reports showed that malicious activity began on July 27 at 01:20:16 UTC and persisted for about one hour and twenty‑seven minutes, coinciding with a notable spike in data downloads on July 27 to 28. Beacon confirmed that there was no evidence of the attacker attempting to maintain persistence within its environment.

The breach exposed personal information such as supporters’ names, email addresses, telephone numbers, and donation records held by charities operating in sectors including healthcare and victim support, though the CRM system did not store sensitive patient information, payment card details, or bank account data. Yorkshire’s Brain Tumour Charity was among the organizations that publicly announced that supporter personal information had been compromised, alongside Shrewsbury and Telford Hospital Charity, the British Deaf Association, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, the Clock Tower Sanctuary, and Victim Support. Beacon noted that, despite the data being encrypted at rest in AWS, the attacker’s valid credentials caused the downloaded files to be decrypted and made readable, and there has been no indication that the stolen data has been published online or otherwise misused.
In response, Beacon reset all credentials for services and accounts integrated with AWS to prevent further unauthorized access and advised its charity customers to report the incident to the UK Information Commissioner’s Office. The Survivor’s Trust, another affected charity, stated on August 13 that the ICO had reviewed its case and concluded that the charity bears no responsibility for the breach. Beacon also reported that it had not detected any attempts by the attacker to maintain persistence within its environment and continued to monitor for any signs of misuse.
