Beacon
Incident posture
Timeline
Summary
A compromised AWS access key, discovered in public JavaScript build artifacts, allowed an attacker to obtain valid credentials and download all data from the CRM platform used by Beacon, affecting over 1500 UK charities including those in healthcare and victim support. The accessed information comprised names, email addresses, telephone numbers, donation records and attached files, though no payment card, bank account or sensitive patient data was stored; the activity lasted about an hour and a half before being contained and the provider reset all related credentials. The provider has reported no evidence of persistent access or public release of the stolen data, and advised its charity customers to notify the UK Information Commissioner's Office about the breach.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 27, 2026 at 01:20:16 UTC, malicious activity began within Beacon’s AWS environment when an unauthorized actor used a compromised access key to gain entry to the CRM platform. The access key was potentially exposed in public JavaScript build artifacts, indicating a development‑process error. The actor’s activity persisted for approximately one hour and twenty‑seven minutes, during which a spike in data transfer was observed consistent with exfiltration. Beacon’s analysis of AWS Cost & Usage reports correlated this period with a significant increase in downloads on July 27 to 28.
Using the valid credentials, the attacker accessed and downloaded all data stored in Beacon’s CRM, including attachment files, affecting the provider’s entire customer base of around 1,500 UK charities. The compromised data comprised supporters’ names, email addresses, telephone numbers, donation records and any attached files, but did not include sensitive patient information, payment card details or bank account information. Among the charities that publicly disclosed impact were The Survivor’s Trust, Shrewsbury and Telford Hospital Charity, British Deaf Association, Yorkshire’s Brain Tumour Charity, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Clock Tower Sanctuary, Victim Support, Myton Hospices and Rowcroft Hospice. Beacon advised its customers to assume that all data they stored in the platform, including attachments, had been downloaded.
Beacon notified all of its customers of the incident after it was first publicly disclosed on August 4, 2026, and urged them to report the breach to the UK Information Commissioner’s Office. In response, the provider reset all credentials for services and accounts integrated with AWS and confirmed that no attempts to maintain persistence within its environment were detected. External cybersecurity experts assisted in containing the incident and launched an investigation into the full circumstances, after which Beacon stated that no ongoing unauthorized access had been observed and that there was no indication the threat actor had published or misused the stolen data. Charities were told they could continue to collect payments via Beacon forms provided they followed the steps in the Security Incident Response Guide to update their payment providers and apps.
Sources
Sources available to members: 2 sources.