A compromised AWS access key exposed the personal data of approximately 1,500 UK charities after a security breach hit the CRM provider Beacon on July 27.
Key Points
- Beacon confirmed that an AWS access key, inadvertently exposed in public Javascript build artifacts, allowed unauthorized access to its entire CRM platform.
- The breach occurred over an 87-minute window on July 27, resulting in the unauthorized download of all customer data and attachments.
- Affected information includes names, email addresses, phone numbers, and donation records, though no payment card or bank details were compromised.
- Beacon has reset all integrated service credentials and confirmed no evidence of persistent access or public data publication by the attacker.
- Impacted organizations include The Survivor’s Trust, the British Deaf Association, and various hospital charities, all of which have been advised to notify the ICO.