Beacon CRM Data Breach Exposes Personal Data of Over 1,000 UK Charities in AWS Credential Compromise – Rescana

August 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: rescana.com

Threat Risk: Medium
Victim: Beacon CRM and over 1,000 UK charities
Incident: Data breach via compromised AWS access keys leaked in public JavaScript artifacts.
Impact: Exfiltration of PII, including names and donation records, for supporters of over 1,000 charities.
Attacker: Unidentified threat actors
Analysis: The breach occurred when an AWS access key was leaked within public JavaScript build artifacts, bypassing encryption at rest. This allowed an unidentified actor to authenticate directly to AWS and exfiltrate a full customer database within 90 minutes. The incident demonstrates a failure in secret management and a lack of automated credential scanning in the CI/CD pipeline.
Recommendations: Implement automated secret scanning in CI/CD pipelines to prevent credential leaks in build artifacts.; Adopt short-lived, temporary credentials via IAM roles instead of long-term static access keys.; Conduct regular audits of client-side JavaScript and public-facing assets for hardcoded secrets.
Source: Rescana

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *