Cyber Incident Victim: Sheffield Hospital Charity
Timeline
Summary
A compromised AWS access key was identified as the likely cause of a cyber‑attack on the CRM provider Beacon, allowing the attacker to download all data stored in the platform, including attachment files, affecting over 1500 UK charities. Although the data was encrypted at rest, the valid credentials enabled decryption during the download, and the malicious activity persisted for about one hour and twenty‑seven minutes before being detected. Beacon reset all related credentials and found no evidence of persistence or subsequent misuse of the stolen information. Affected charities were advised to report the incident to the UK Information Commissioner’s Office, with one organization confirming that the regulator deemed it not responsible for the breach. Public statements were issued by several charities, including Sheffield Hospital Charity, noting that supporter names, email addresses, telephone numbers and donation records had been exposed, while no patient health details, payment card numbers or bank account information were stored in the compromised system.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A compromised AWS access key was identified as the likely root cause of the cyber‑attack on the CRM provider Beacon, with the key potentially exposed in public Javascript build artifacts. Using these valid credentials, the attacker accessed and downloaded all data stored in Beacon’s CRM platform, including attachment files, affecting the provider’s entire customer base of approximately 1500 UK charities. Analysis of Beacon’s AWS Cost & Usage reports showed that the malicious activity began on July 27 at 01:20:16 UTC and continued for about one hour and twenty‑seven minutes, coinciding with a notable spike in data downloads on July 27 to 28. Beacon stated that it did not detect any attempts by the attacker to maintain persistence within its environment and subsequently reset all credentials for services and accounts integrated with AWS to prevent further unauthorized access.

The data exposed through the breach included supporters’ names, email addresses, telephone numbers, and donation records, which could be used to launch social engineering attacks against individuals; the CRM system did not contain sensitive patient information, payment card details, or bank account information. Sheffield Hospital Charity was among the charities that publicly announced that personal information of its supporters had been compromised, joining other organizations such as Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire's Brain Tumour Charity, Priscilla Bacon Hospice Charity, the Clock Tower Sanctuary, and Victim Support. The Information Commissioner’s Office reviewed a related case involving The Survivor’s Trust and concluded that the charity bore no responsibility for the breach, a finding that was communicated to other affected charities, including Sheffield Hospital Charity.
In response, Beacon advised all its charity customers to report the incident to the UK Information Commissioner’s Office, and Sheffield Hospital Charity followed this guidance by informing its supporters of the compromise. The charity urged its supporters to remain alert to potential scams in the weeks following the announcement. Beacon confirmed that there had been no indication that the threat actor had published the stolen data online or otherwise misused it, and it maintained that the breach did not involve any persistent access to its systems.
