Cyber Incident Victim: The Survivor's Trust
Timeline
Summary
A compromised AWS access key allowed an attacker to download all data from the CRM platform used by Beacon, affecting over 1500 UK charities including The Survivor's Trust. The attacker used valid credentials to access and decrypt files, resulting in the exposure of supporters’ names, email addresses, telephone numbers and donation records, while no payment card or bank details were stored. The incident lasted about an hour and a half, with no evidence of persistence or subsequent misuse of the data, and the Information Commissioner’s Office cleared the charity of responsibility. Other charities such as Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire's Brain Tumour Charity, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, the Clock Tower Sanctuary and Victim Support also reported similar exposures.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 12, Beacon, the CRM provider, issued an incident update stating that a compromised AWS access key was the likely root cause of the cyber‑attack on its platform. The provider said the access key had potentially been exposed in public JavaScript build artifacts, indicating a development‑process error. Analysis of Beacon’s AWS Cost & Usage reports showed that malicious activity began on July 27 at 01:20:16 UTC and continued for approximately one hour and twenty‑seven minutes, coinciding with a notable spike in data downloads on July 27‑28.

Using the valid credentials, the attacker accessed and downloaded all data stored in Beacon’s CRM platform, including attachment files, affecting the provider’s entire customer base of roughly 1,500 UK charities. The exposed information comprised supporters’ names, email addresses, telephone numbers and donation records; the CRM system did not contain sensitive patient data, payment card details or bank account information. Because the data was encrypted at rest in AWS, the attacker’s valid credentials caused AWS to decrypt the downloads, making the information readable. The breach impacted charities working in sensitive sectors such as healthcare and victim support, including The Survivor’s Trust, Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire’s Brain Tumour Charity, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, the Clock Tower Sanctuary and Victim Support.
Beacon reported that it found no evidence of the attacker attempting to maintain persistence in its environment and subsequently reset all credentials for services and accounts integrated with AWS to prevent further unauthorized access. The provider advised its charity customers to report the incident to the UK Information Commissioner’s Office. The Survivor’s Trust announced on August 13 that the ICO had reviewed its case and determined the charity bears no responsibility for the breach, urging supporters to remain alert to possible scams. As of the August 13 statement, there had been no indication that the stolen data had been published online or otherwise misused.
