Menu
Browse
Date

Jul 2026

Location

United Kingdom

Status

Unknown

Updated

2026-08-16 16:52

Timeline
Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

A compromised AWS access key used by the CRM provider Beacon allowed an attacker to download all data stored in the platform, affecting over 1500 UK charities including Shrewsbury and Telford Hospital Charity. The exposed information consisted of supporters’ names, email addresses, telephone numbers and donation records, while no patient health details, payment card numbers or bank account data were held in the system. Although the data was encrypted at rest, the valid credentials enabled decryption during the download, which occurred over a period of about one hour and twenty‑seven minutes. Beacon reported no signs of persistent access, reset all related credentials and said there is no evidence the stolen data has been published or misused. Affected charities have been instructed to notify the UK Information Commissioner’s Office, and one victim noted that the ICO has already determined the charity bears no responsibility for the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

A compromised AWS access key was the likely root cause of the cyber‑attack on CRM provider Beacon, which exposed personal information held by around 1500 UK charities. The provider said the access key was potentially exposed in public Javascript build artifacts, indicating a software development error. Using these valid credentials, the attacker accessed and downloaded all data contained within the Beacon CRM platform, including attachment files. Malicious activity began on July 27 at 01:20:16 UTC and lasted approximately one hour and 27 minutes, as identified from Beacon’s AWS Cost & Usage reports. The accessed data comprised supporters’ names, email addresses, telephone numbers and donation records, while the CRM did not hold sensitive patient information, payment card details or bank account information. Although the data was encrypted at rest in AWS, the valid credentials caused AWS to decrypt the downloads, making the information readable to the attacker.

Cyber Incident Image

Shrewsbury and Telford Hospital Charity was among the charities that publicly announced the compromise of supporters’ personal information. The charity reported the breach to the United Kingdom’s Information Commissioner’s Office (ICO) as advised by Beacon. The ICO reviewed the case and concluded that the charity holds no responsibility for the breach. In its statement, the charity urged supporters to stay alert to potential scams in the coming weeks. Similar public announcements were made by other affected charities such as the British Deaf Association and Yorkshire's Brain Tumour Charity. The type of data thought to have been affected included supporters’ names, email addresses, telephone numbers and donation records, which could be used for social engineering attacks.

Beacon responded by resetting all credentials for services and accounts integrated with AWS to prevent repeat unauthorized access. The provider stated it has not detected any attempts by the attacker to maintain persistence within its environment. Beacon’s analysis of AWS Cost & Usage reports showed the malicious activity window and correlated it with a significant increase in data downloads on July 27 to 28. To date, there has been no indication that the threat actor has published the stolen data online or otherwise misused it. Beacon also advised all its charity customers, including Shrewsbury and Telford Hospital Charity, to report the breach to the ICO. The provider emphasized that the breach did not involve sensitive patient information, payment card details or bank account information.

Sources
Sources available to members
1 source