logo

AWS key exposed in JavaScript may have lit way to Beacon's charity data

ID: 8ece4560-5dd8-54d4-bacc-7c1fa67629ae

STIX ID: report--8ece4560-5dd8-54d4-bacc-7c1fa67629ae

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

...
...

Beacon, a CRM provider for charities, reported that an AWS access key potentially exposed in public JavaScript build artifacts likely enabled an attacker to copy and probably download its entire customer database and attachments. The malicious activity occurred on 27–28 July 2026, lasted about 1 hour 27 minutes, and has affected numerous charities; Beacon confirmed a database copy was made but cannot determine which specific records left its systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.