Menu
Browse

Cyber Incident Victim: Priscilla Bacon Hospice Charity

Date

Jul 2026

Location

United Kingdom

Status

Unknown

Updated

2026-08-16 16:49

Timeline
Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

A compromised AWS access key was the likely root cause of a cyber‑attack on the CRM provider Beacon, which exposed personal data held by over 1,500 UK charities. The attacker used the valid credentials to download all data from the platform, including attachment files, while the information remained encrypted at rest but was decrypted during the download. The malicious activity lasted approximately one hour and twenty‑seven minutes, after which Beacon reset all related credentials and found no evidence of persistence or subsequent misuse of the stolen data. Several charities, including Priscilla Bacon Hospice Charity, publicly announced that supporter names, email addresses, telephone numbers and donation records had been affected, noting that no patient health information, payment card details or bank account data were stored in the compromised system.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 27, 2026, at 01:20:16 UTC, an analysis of Beacon’s AWS Cost & Usage reports showed the start of malicious activity that lasted approximately one hour and twenty‑seven minutes, coinciding with a notable spike in data downloads between July 27 and July 28. The activity stemmed from a compromised AWS access key that had been inadvertently exposed in public JavaScript build artifacts during software development. Using these valid credentials, the attacker was able to authenticate to Beacon’s CRM platform and download all data stored within it, including attachment files, affecting the provider’s entire customer base of roughly 1,500 UK charities. Although the data was encrypted at rest in AWS, the attacker’s valid credentials caused AWS to decrypt the information during download, making it readable. Beacon confirmed that there was no evidence of the attacker attempting to maintain persistence within its environment after the download window closed.

Cyber Incident Image

As a result of the breach, Priscilla Bacon Hospice Charity was among the charities that publicly announced that supporters’ personal information had been compromised, alongside organizations such as Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire’s Brain Tumour Charity, Sheffield Hospital Charity, the Clock Tower Sanctuary and Victim Support. The data believed to have been accessed included supporters’ names, email addresses, telephone numbers and donation records, which could be used to facilitate social engineering attacks, while the CRM system did not contain sensitive patient information, payment card details or bank account details. Beacon notified all affected charities and advised them to report the incident to the UK Information Commissioner’s Office (ICO). In response, Beacon reset all credentials for services and accounts integrated with AWS to prevent any further unauthorized access.

The ICO reviewed the case submitted by The Survivor’s Trust, another affected charity, and concluded that the charity bore no responsibility for the breach. No indication has been found that the threat actor published the stolen data online or otherwise misused it. Priscilla Bacon Hospice Charity, like the other affected organizations, has been urged to remain vigilant for potential scams targeting supporters in the weeks following the public disclosure. The incident remains under review by the relevant authorities, with no further unauthorized activity detected to date.

Sources
Sources available to members
1 source