Cyber Incident Victim: Clock Tower Sanctuary
Timeline
Summary
A compromised AWS access key, discovered in public JavaScript build artifacts, allowed an attacker to download all data from Beacon’s CRM platform, affecting over 1,500 UK charities including the Clock Tower Sanctuary. The exposed data comprised supporters’ names, email addresses, telephone numbers and donation records, though no payment card or bank information was stored. Although the information was encrypted at rest, the valid credentials caused AWS to decrypt it during download, and the unauthorized activity lasted approximately one hour and twenty‑seven minutes before the provider reset all related credentials and found no evidence of persistence or public release of the stolen data.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 27, 2026, at 01:20:16 UTC, malicious activity began when an attacker used a compromised AWS access key to gain entry to Beacon’s CRM platform. The access key had potentially been exposed in public JavaScript build artifacts, according to Beacon’s August 12 incident update. Using the valid credentials, the attacker downloaded all data stored in the CRM, including attachment files, over a period lasting approximately one hour and twenty‑seven minutes. Although the data was encrypted at rest in AWS, the attacker’s valid credentials caused AWS to decrypt the information during download, making it readable. Beacon’s analysis of AWS Cost & Usage reports showed a notable spike in data transfers between July 27 and July 28 that corresponded with the attack window. The provider reported no evidence of the attacker attempting to maintain persistence within its environment after the downloads concluded.

The breach affected Beacon’s entire customer base of roughly 1,500 UK charities, exposing personal information such as supporters’ names, email addresses, telephone numbers, and donation records. The compromised CRM did not contain sensitive patient data, payment card details, or bank account information. Among the charities that publicly acknowledged the compromise were Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire’s Brain Tumour Charity, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Victim Support, and the homelessness charity Clock Tower Sanctuary. Clock Tower Sanctuary, like the other affected charities, advised its supporters to remain alert to potential scams and reported the incident to the UK Information Commissioner’s Office. The Survivor’s Trust, another victim, stated that the ICO had reviewed its case and determined the charity bore no responsibility for the breach.
In response, Beacon reset all credentials for services and accounts integrated with AWS to prevent further unauthorized access and confirmed that it had not detected any attempts by the threat actor to maintain persistence. The provider also notified its charity customers, urging them to report the breach to the ICO. As of the August 13 article, there had been no indication that the stolen data had been published online or otherwise misused by the attacker. Clock Tower Sanctuary, along with the other charities, made public statements confirming that supporter personal information had been compromised and continued to monitor for any follow‑on activity.
