Exposed AWS Key Leads to Data Breach Affecting Over 1500 UK Charities
A data breach at CRM provider Beacon, affecting over 1500 UK charities, was caused by an exposed AWS access key. The key was potentially exposed in public Javascript build artifacts, allowing attackers to access and download all data within the CRM platform. This includes personal information from charities in sensitive sectors like healthcare and victim support. The breach began on July 27 and lasted for approximately 87 minutes. Beacon has reset all credentials to prevent further unauthorized access. There is no evidence yet that the stolen data has been published or misused.