Cyber Incident Victim: Victim Support
Timeline
Summary
A compromised AWS access key allowed an attacker to download data from the CRM platform of Beacon, affecting over 1,500 UK charities including Victim Support. The exposed information comprised supporters’ names, email addresses, telephone numbers and donation records, though no payment card or bank details were stored. The attacker’s activity lasted approximately one and a half hours before detection, and Beacon has since reset all related credentials and found no evidence of persistence or public release of the data. Affected charities have been advised to notify the UK Information Commissioner’s Office, with some confirming they bear no responsibility for the breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 27, 2026, at 01:20:16 UTC, malicious activity began when an attacker used a compromised AWS access key to access the Beacon CRM platform. The access key had been exposed in public JavaScript build artifacts, indicating a software development error. Using these valid credentials, the attacker downloaded all data stored in the CRM, including attachment files, over a period of approximately one hour and twenty‑seven minutes. Although the data was encrypted at rest in AWS, the valid credentials caused AWS to decrypt the information during download, making it readable. Beacon’s analysis of AWS Cost & Usage reports showed a spike in data downloads on July 27‑28 that matched the activity window. The provider reported no evidence of the attacker attempting to maintain persistence within its environment.

The breach affected Beacon’s entire customer base of roughly 1,500 UK charities, among them Victim Support, which publicly announced that its supporters’ personal information had been compromised. The exposed data included supporters’ names, email addresses, telephone numbers, and donation records, but did not contain sensitive patient information, payment card details, or bank account numbers. Other charities that made similar announcements were Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire’s Brain Tumour Charity, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, and the Clock Tower Sanctuary. Beacon advised all affected charities to report the incident to the UK Information Commissioner’s Office (ICO). The Survivor’s Trust, a victim‑support charity, stated that the ICO had reviewed its case and concluded the charity bears no responsibility for the breach.
In response, Beacon reset all credentials for services and accounts integrated with AWS to prevent further unauthorized access. The provider said it has not detected any attempts by the threat actor to publish or misuse the stolen data online. Charities, including Victim Support, urged their supporters to remain alert to potential scams that could arise from the exposed contact information. No further details about data misuse or additional victim impact were provided in the source material.
