A compromised AWS access key led to a cyber-attack on the CRM provider Beacon, affecting personal information of over 1500 UK charities. The key was publicly exposed during software development, allowing the attacker to download data, including sensitive information of supporters, without detection in real time. Although data was encrypted at rest in AWS, it was decrypted during access.
Beacon has advised its customers to report the breach to the UK Information Commissioner's Office and stated that they reset all credentials to prevent further unauthorized access. Confirmed victims have been aware of their compromised data and urged vigilance against potential scams.