AWS Key Blunder in JavaScript Might Have Exposed Beacon’s Charity Information

Beacon’s Recent Technical Misstep

Hey there, everyone! So, Beacon, those CRM guys for charities and nonprofits, have really messed up. Looks like they’ve got an AWS access key that got “possibly exposed in public JavaScript build artifacts” during that breach in July. Can you believe it? This is their first update regarding the incident in ages. If the key was out in the open, it raises questions about why Beacon’s development pipeline and code checks didn’t catch it. Pretty careless, acting like a right mess.

Database Trouble: What Actually Occurred?

Beacon’s being honest, using more formal language this time. A copy of the database was taken and likely accessed in a readable format. “This update confirms… that a copy of the database which stores all Beacon customer data, including attachment files, was created and probably downloaded in a readable format by the threat actor,” stated CTO David Simpson, without a trace of ‘apology’.

Data Transfer Chaos

Examination of those AWS Cost & Usage reports from May to July 2026 indicated a sharp increase in data transfer on July 27-28, 2026. Just when the trouble was occurring, suggesting significant downloads were happening. Beacon’s logs aren’t revealing exactly which records were stolen, but a copy of the database was indeed made.

Assessing the Damage: What Was Revealed?

In an FAQ that came with the update, Beacon is advising customers to consider what they kept in their CRM. Many charities mention the data mainly consisted of personal information and donation records. Simpson believes Beacon’s AWS data was encrypted at rest, but that troublesome access key might’ve allowed the attacker to grab it in a readable format. The trouble reportedly began in the early hours of July 27. The entire incident lasted an hour and 27 minutes, though Beacon claims no persistent threats were left behind.

What’s Next: Beacon’s Ongoing Troubles

Simpson’s providing a warning to customers, stating there are aspects of this incident that they may never comprehend, and they won’t be revealing more details to maintain their security. They’ll send a summary to customers once the investigation concludes in a few weeks. But don’t expect much more than what’s already been shared on Wednesday.

Charities in the Line of Fire

Since Beacon disclosed the information on August 4, numerous charities have come forward saying they’re impacted, adding to the list each day. Early responses included Molly Rose Foundation, Macmillan Cancer Support Jersey, and English National Ballet. Now Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral are also declaring ‘yes, we’re affected’.

Charity Commission Overwhelmed

The Charity Commission is receiving a massive influx of serious incident reports, resulting in response delays. “We appreciate your patience and understanding as we prioritize instances of the greatest risk,” they stated, which is a fancy way of saying ‘we’re extremely busy’.

Summary: Charity Data Mismanagement – It’s a Major Blunder!

So, there you go! Beacon has a significant number of issues to tackle, and charities are caught in the middle. Who would have thought a silly AWS key could lead to such a mess? Stay informed, and remember – keep your keys safe, everyone!