Victim Support
Incident posture
Linked entities
- Victim
- Victim Support
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A compromised AWS access key that had been inadvertently left in public JavaScript build artifacts allowed an attacker to gain valid credentials to Beacon CRM’s cloud environment and exfiltrate the full customer database and attached files. The breach exposed personal information such as names, email addresses, telephone numbers and donation records from over a thousand UK charities, including organizations in the healthcare and victim support sectors such as Victim Support. No payment card, bank account or patient data was stored in the affected system, and the attacker did not deploy malware or establish persistence. The unauthorized access lasted approximately one and a half hours before being detected, after which credentials were rotated, exposed secrets removed and additional monitoring tools deployed. Regulatory bodies were notified and the UK Information Commissioner’s Office later cleared several charities of responsibility for the breach.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 27, 2026, at 01:20:16 UTC, an attacker began exploiting a compromised AWS access key that had been inadvertently exposed in public JavaScript build artifacts associated with Beacon CRM. Using the valid credentials, the attacker authenticated directly to Beacon’s AWS environment and initiated a data exfiltration session that lasted approximately one hour and twenty‑seven minutes, during which a significant spike in AWS data transfers was observed. The intrusion was not detected until July 29, 2026, when Beacon’s internal monitoring identified the anomalous activity. Public disclosure of the breach was made by Beacon on August 4, 2026, after initial customer notifications began on August 3, 2026 and further technical details were shared by the company’s CTO on August 12, 2026.
The compromised data consisted of personal information belonging to supporters and donors of Beacon’s charity customers, including names, email addresses, telephone numbers, donation records, and file attachments, while payment card details, bank account information, and patient data were not stored in the affected environment. Beacon reported that the breach impacted over 1,000 UK charities, with later assessments indicating that around 1,500 charitable organizations were affected, encompassing entities such as Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice, The Survivor’s Trust, Justice for Colombia, Center for Sustainable Energy, British Deaf Association, Yorkshire's Brain Tumour Charity, Shrewsbury and Telford Hospital Charity, the Clock Tower Sanctuary, and Victim Support. The data was encrypted at rest in AWS, but because the attacker used valid credentials, the information was decrypted during download and made available in readable form. No malware, persistence mechanisms, or post‑exploitation tools were identified during the investigation, and no evidence of the stolen data appearing on dark web leak sites or being used for extortion has been reported.
In response, Beacon rotated all AWS‑integrated credentials, removed the exposed build parameters from client‑side JavaScript, and deployed additional security tooling including endpoint detection and SentinelOne Cloud Native Security to contain the incident and prevent further unauthorized access. Affected charities were advised to report the breach to the UK Information Commissioner’s Office, and The Survivor’s Trust confirmed on August 13, 2026 that the ICO had reviewed its case and concluded the charity bore no responsibility for the incident. No ongoing unauthorized access has been detected since the initial containment, and Beacon notified the ICO and other regulatory authorities as required under data protection legislation.
Sources
Sources available to members: 2 sources.