Menu
Browse

Cyber Incident Victim: British Deaf Association

Date

Jul 2026

Location

United Kingdom

Status

Unknown

Updated

2026-08-16 17:11

Timeline
Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

The breach stemmed from an exposed AWS access key that was likely leaked in public JavaScript build artifacts, allowing an attacker to use valid credentials to download all data from Beacon’s CRM platform, including attachment files, affecting over 1500 UK charities. Although the data was encrypted at rest, the attacker’s access caused AWS to decrypt it during download, exposing supporters’ names, email addresses, telephone numbers and donation records, but not payment card or bank details. Beacon reported the activity lasted about an hour and a half, found no persistence, and reset all related credentials. Charities, including the British Deaf Association, Shrewsbury and Telford Hospital Charity and Yorkshire's Brain Tumour Charity, publicly disclosed that supporter information had been compromised and were advised to report the incident to the UK Information Commissioner’s Office, which has already cleared some victims of responsibility.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

A compromised AWS access key was identified as the likely root cause of the cyber‑attack on the CRM provider Beacon, with the key potentially exposed in public Javascript build artifacts due to an error during software development. Beacon reported that the attacker used these valid credentials to access and download all data stored in its CRM platform, including attachment files, thereby affecting its entire customer base of approximately 1500 UK charities. Analysis of Beacon’s AWS Cost & Usage logs showed that malicious activity began on July 27 at 01:20:16 UTC and continued for about one hour and twenty‑seven minutes, a period that coincided with a notable spike in data downloads. Although the data was encrypted at rest in AWS, the attacker’s valid credentials caused the downloads to be decrypted by AWS and made available in readable form, and Beacon found no evidence that the attacker attempted to maintain persistence in its environment.

Cyber Incident Image

The breach impacted charities operating in sensitive sectors such as healthcare and victim support, and among those publicly acknowledging the compromise were Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Yorkshire's Brain Tumour Charity, with additional announcements from Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, the Clock Tower Sanctuary, and Victim Support. The specific data elements believed to have been exposed include supporters’ names, email addresses, telephone numbers, and donation records, which could enable social engineering attacks, while the CRM system did not contain sensitive patient information, payment card details, or bank account data. Beacon advised all affected charities to report the incident to the UK Information Commissioner’s Office, and one confirmed victim, The Survivor’s Trust, noted that the ICO had reviewed its case and concluded the charity bore no responsibility for the breach, urging supporters to stay alert to potential scams.

In response, Beacon reset all credentials for services and accounts linked to AWS to prevent further unauthorized access and stated that there has been no indication that the threat actor has published or misused the stolen data online. Charities that made public announcements, including the British Deaf Association, have informed their supporters about the nature of the compromised information and recommended vigilance against phishing or fraudulent communications. The incident remains under review by the ICO, and no further details about data misuse have been disclosed.

Sources
Sources available to members
1 source