AWS key exposed in JavaScript may have lit way to Beacon’s charity data
Beacon, a customer relationship management provider for charities and non-profits, believes an AWS access key potentially exposed in publicly available JavaScript build files was the likely route into its July cyberattack. The company now says an attacker copied its entire customer database, including attachment files, and probably downloaded substantial amounts in readable form, raising concerns for charities holding personal and donation information on the platform.
Beacon found unusually high data-transfer activity on 27–28 July 2026, consistent with the attack, which began on 27 July and lasted one hour and 27 minutes. Its logs cannot identify exactly which records were taken, and it has not said how many of its more than 1,500 customers were affected; however, several prominent charities have confirmed exposure. Although the AWS data was encrypted at rest, Beacon says the compromised key may have enabled readable access, and it has advised customers to assess whether they need to notify affected people.
- Beacon suspects an exposed AWS key enabled its July breach.
- The attacker likely downloaded readable charity customer data.
- Affected charities must assess notification risks themselves.