CSIDB logo
Incident

Victim Support

Incident posture

Attack window
Jul 2026
Location
United Kingdom
Status
Resolved
CIA posture
Available to members
Updated
2026-08-26 19:06

Linked entities

Victim
Victim Support
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2026
Discovered
Jul 2026
Disclosed
Aug 2026
Resolved
Jul 2026

Summary

A compromised AWS access key that had been inadvertently left in public JavaScript build artifacts allowed an attacker to gain valid credentials to Beacon CRM’s cloud environment and exfiltrate the full customer database and attached files. The breach exposed personal information such as names, email addresses, telephone numbers and donation records from over a thousand UK charities, including organizations in the healthcare and victim support sectors such as Victim Support. No payment card, bank account or patient data was stored in the affected system, and the attacker did not deploy malware or establish persistence. The unauthorized access lasted approximately one and a half hours before being detected, after which credentials were rotated, exposed secrets removed and additional monitoring tools deployed. Regulatory bodies were notified and the UK Information Commissioner’s Office later cleared several charities of responsibility for the breach.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 27, 2026, at 01:20:16 UTC, an attacker began exploiting a compromised AWS access key that had been inadvertently exposed in public JavaScript build artifacts associated with Beacon CRM. Using the valid credentials, the attacker authenticated directly to Beacon’s AWS environment and initiated a data exfiltration session that lasted approximately one hour and twenty‑seven minutes, during which a significant spike in AWS data transfers was observed. The intrusion was not detected until July 29, 2026, when Beacon’s internal monitoring identified the anomalous activity. Public disclosure of the breach was made by Beacon on August 4, 2026, after initial customer notifications began on August 3, 2026 and further technical details were shared by the company’s CTO on August 12, 2026.

The compromised data consisted of personal information belonging to supporters and donors of Beacon’s charity customers, including names, email addresses, telephone numbers, donation records, and file attachments, while payment card details, bank account information, and patient data were not stored in the affected environment. Beacon reported that the breach impacted over 1,000 UK charities, with later assessments indicating that around 1,500 charitable organizations were affected, encompassing entities such as Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice, The Survivor’s Trust, Justice for Colombia, Center for Sustainable Energy, British Deaf Association, Yorkshire's Brain Tumour Charity, Shrewsbury and Telford Hospital Charity, the Clock Tower Sanctuary, and Victim Support. The data was encrypted at rest in AWS, but because the attacker used valid credentials, the information was decrypted during download and made available in readable form. No malware, persistence mechanisms, or post‑exploitation tools were identified during the investigation, and no evidence of the stolen data appearing on dark web leak sites or being used for extortion has been reported.

In response, Beacon rotated all AWS‑integrated credentials, removed the exposed build parameters from client‑side JavaScript, and deployed additional security tooling including endpoint detection and SentinelOne Cloud Native Security to contain the incident and prevent further unauthorized access. Affected charities were advised to report the breach to the UK Information Commissioner’s Office, and The Survivor’s Trust confirmed on August 13, 2026 that the ICO had reviewed its case and concluded the charity bore no responsibility for the incident. No ongoing unauthorized access has been detected since the initial containment, and Beacon notified the ICO and other regulatory authorities as required under data protection legislation.

Sources

Sources available to members: 2 sources.

CSIDB