Urgent.News

What's breaking now, across thousands of outlets.

Tech

AWS key exposed in JavaScript may have lit way to Beacon's charity data

CRM provider confirms customer database was copied and probably downloaded in readable form

AWS key exposed in JavaScript may have lit way to Beacon's charity data

Beacon, a CRM service catering to charities and nonprofits, has disclosed that an exposed AWS access key in public JavaScript build artifacts is the primary suspect in its July security breach. The revelation emerged in the company's latest update on the incident, over a week after the initial attack. The access key's exposure has raised concerns about deficiencies in Beacon's development pipeline and code review processes.

CTO David Simpson confirmed that a copy of Beacon's database, housing all customer data, including attachments, was created and likely downloaded in a readable format by the threat actor. Beacon's technical team analyzed AWS Cost & Usage reports from May to July 2026, which revealed a significant surge in data transfers on July 27-28, 2026, aligning with the malicious activity.

While Beacon's logs cannot pinpoint the exact records exfiltrated, the company confirmed a database copy was taken, containing all customer data and attachments.

Customers are advised to evaluate their potential exposure by reviewing what they stored in the CRM instance. Many affected charities reported that the data primarily consisted of personal information and donation details. Beacon's AWS data was encrypted at rest, but the compromised access key may have facilitated the extraction of plaintext data.

The malicious activity commenced early on July 27, consistent with Beacon's initial timeline estimate. The company, which serves over 1,500 customers, has not determined how many experienced data loss.

The breach persisted for 1 hour and 27 minutes before the attacker abandoned persistence mechanisms in AWS. Simpson cautioned that certain incident details may remain unknown and that further insights won't be shared to safeguard Beacon's security. He promised to provide customers with a comprehensive summary upon investigation completion in a few weeks, though he warned the forthcoming update may not contain extensive details.

Beacon published this final update on August 4, 2026, following the growing list of affected charities, including the Molly Rose Foundation, Macmillan Cancer Support Jersey, the English National Ballet, Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral. The Charity Commission reported a surge in serious incident reports from affected charities, leading to delays in responses.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Thursday 13 August →