AWS key exposed in JavaScript may have lit way to Beacon's charity data
ID: 8ece4560-5dd8-54d4-bacc-7c1fa67629ae
STIX ID: report--8ece4560-5dd8-54d4-bacc-7c1fa67629ae
Feed Name: The Register (Security)
Threat Score
Beacon, a CRM provider for charities, reported that an AWS access key potentially exposed in public JavaScript build artifacts likely enabled an attacker to copy and probably download its entire customer database and attachments. The malicious activity occurred on 27–28 July 2026, lasted about 1 hour 27 minutes, and has affected numerous charities; Beacon confirmed a database copy was made but cannot determine which specific records left its systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
