Clock Tower Sanctuary
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
Clock Tower Sanctuary is a charity based in the United Kingdom that provides services and support to people in need within its community. While the prompt offers limited information about the organisation's specific day-to-day programmes, core mission or service user base, it is established as a registered UK charity that relies on a supporter and donor ecosystem to sustain its operations. The organisation engages with the public through fundraising activities and maintains records of its supporters, including contact details and donation histories.
Clock Tower Sanctuary was among more than 1,500 UK charities affected by a significant data security incident that came to light in July 2026. The breach stemmed from a compromised Amazon Web Services (AWS) access key that was inadvertently embedded in public JavaScript build artefacts associated with Beacon, a CRM platform widely used across the UK charity sector. Because the exposed access key was valid, AWS automatically decrypted the stored data as it was being exfiltrated, even though the underlying information had been encrypted at rest. The stolen dataset for affected organisations such as Clock Tower Sanctuary included supporter names, email addresses, telephone numbers and donation records. Crucially, no payment card or bank account details were held within the compromised CRM environment, limiting the financial exposure of those impacted. The unauthorised access persisted for approximately one hour and twenty-seven minutes before the hosting provider reset all related credentials and confirmed there was no evidence of attacker persistence or public dissemination of the stolen information.
As a charity operating in the UK, Clock Tower Sanctuary falls within a sector that is heavily reliant on third-party technology providers for fundraising, donor relationship management and operational administration. Its inclusion among the organisations affected by the Beacon CRM incident illustrates how vulnerabilities in widely shared software supply chains can simultaneously impact large numbers of charities regardless of their individual size or resources. The prompt does not provide explicit information regarding the organisation's annual income, staff headcount, number of beneficiaries, governance structure or any parent or subsidiary relationships, so no further detail on scale, ownership or corporate structure can be reliably stated. What is clear is that Clock Tower Sanctuary is a UK-registered charitable entity that maintains a donor and supporter database through a third-party CRM platform, placing it within the broader landscape of small and medium-sized charities that depend on shared digital infrastructure for engagement and fundraising activities.
Incidents
1 incident linked to this organisation.