Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology

Exposed AWS key in JavaScript build may have enabled theft of Beacon charity data

Beacon, a CRM service for charities, says a publicly visible AWS access key in its JavaScript build likely allowed attackers to copy and download its customer database in readable form.

Beacon, which supplies CRM software to charities and nonprofits, has linked its recent security incident to an AWS access key that appeared in publicly accessible JavaScript build files. The company’s CTO, David Simpson, stated that the key likely enabled the threat actor to create a complete copy of the customer database, including attached files, and to download it in a readable format. Cost and usage data from May to July 2026 revealed a pronounced increase in data transfer on 27-28 July, aligning with the timeline of the malicious activity that began in the early hours of July 27.

The breach persisted for one hour and 27 minutes, with no evidence of the attacker establishing persistence in the AWS environment. While Beacon’s data at rest was encrypted, the exposed key may have bypassed that protection. With over 1,500 charitable clients, the firm has asked them to evaluate the potential exposure of personal and donation information and promises a further summary once the investigation concludes.

Why it matters

A leaked AWS key exposed sensitive donor and personal data of many charities, risking privacy breaches and trust.

In this story

AWS access keyJavaScript build artifactdata breachcharity CRMdatabase downloadcost and usage reportencryption at rest