AWS Key Exposure Leads to Charity Data Exfiltration
Beacon, a CRM provider, confirmed its customer database was copied and likely downloaded in readable form. An AWS key, exposed within JavaScript, is believed to have provided the access vector. The incident resulted in the potential exfiltration of sensitive charity data. The full scope of the compromise is under investigation.
Severity: Critical · Category: Data Exfiltration
Impact: Customer database copied and potentially downloaded in readable form, exposing sensitive charity data.
Source: The Register · Aug 13 2026 · Original source
What Happened
Beacon, a CRM provider for charities and nonprofits, experienced a security incident where an AWS access key was "potentially exposed in public JavaScript build artifacts." This exposure is considered the leading suspect in a breach that occurred in July. The malicious activity began in the early hours of July 27 and lasted for one hour and 27 minutes. During this time, a copy of the database containing all Beacon customer data, including attachment files, was made and assessed to have been likely downloaded in a readable format by the threat actor. Although Beacon's AWS data was encrypted at rest, the compromised access key may have allowed the attacker to retrieve it in readable form.
Timeline
- July 27, 2026 — Malicious activity began in the early hours.
- July 27-28, 2026 — Significant increase in data transfer observed in AWS Cost & Usage reports, correlating with malicious activity.
- August 4, 2026 — Beacon disclosed the attack.
- August 13, 2026 — Beacon provided its first update on the attack, more than a week after disclosure.
Technical Analysis
The suspected root cause of the incident is an AWS access key that was "potentially exposed in public JavaScript build artifacts." This exposure raises questions regarding the efficacy of Beacon's development pipeline and code review controls. Analysis of AWS Cost & Usage reports for May-July 2026 revealed a significant increase in data transfer on July 27-28, 2026, which correlated with the malicious activity and supported the assessment of substantial data downloads. While Beacon's AWS data was encrypted at rest, the compromised access key likely enabled the attacker to bypass this protection and retrieve the data in readable form. Beacon confirmed that the attacker did not establish any persistence mechanisms in AWS during the incident.
Impact
The incident resulted in a confirmed copy of Beacon's entire customer database, including attachment files, being made and likely downloaded in a readable format. Beacon serves over 1,500 customers, primarily charities and nonprofits. While the company's logs cannot reveal which specific records were exfiltrated, many affected charities have confirmed that the data mainly pertains to personal information and details about donations. Several high-profile charities, including Molly Rose Foundation, Macmillan Cancer Support Jersey, English National Ballet, Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral, have confirmed they are affected. The Charity Commission reported receiving a high volume of serious incident reports from charities, causing delays in their responses.
Discovery & Response
Beacon disclosed the attack on August 4 and provided its first update on the incident on August 13, more than a week later. The company conducted an analysis of AWS Cost & Usage reports across May-July 2026, which showed a significant increase in data transfer correlating with the malicious activity. Beacon's root cause analysis identified the start of the malicious activity in the early hours of July 27. CTO David Simpson stated that some details about the incident may never be discovered, and other information would be withheld to protect Beacon's security posture. Beacon advised its customers to assess their likely exposure by reviewing the data they stored in their CRM instances and to make their own risk assessments regarding onward notification to impacted data subjects.
How Fencio prevents this
Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.
Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.