A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities
Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

Key points
- Hackers stole data from Beacon CRM, a UK company whose software is used by more than 1,000 charities and non-profit organisations.
- The earliest malicious activity was detected on 27 July 2025, with data transferred on 27 to 28 July.
- Criminals likely used a leaked AWS access key found in publicly visible code to enter Beacon's systems.
- Personal information including names, phone numbers, email addresses and postal addresses may have been taken; no bank or payment details were stored on the system.
- The UK Charity Commission is monitoring the situation and has issued guidance to affected organisations.
Beacon is a cloud-based CRM: software that runs on the internet and helps organisations track donors, volunteers and fundraising. Built specifically for the charity sector, it was quietly doing that job for more than a thousand UK non-profits until late July.
On 27 July, criminals broke in. By the morning of the 28th, they'd almost certainly copied every database Beacon held.
How did the hackers get in?
They used a leaked AWS access key. AWS (Amazon Web Services) is the cloud platform Beacon ran its systems on, essentially rented servers and storage. An access key is a string of characters that acts like a password, letting software authenticate to that cloud environment automatically.
Beacon's investigation found the key had likely been left inside publicly available JavaScript build artifacts: the packaged files a software team produces when compiling and publishing their code. Leaving a credential inside one is a well-known and painfully common mistake. Anyone who downloaded or inspected those files could've read the key and walked straight into Beacon's AWS environment, no phishing or malware needed.
It's the same failure class we covered on 6 August in our look at a healthcare software provider's breach, where a single stolen developer credential unravelled four years of layered defences. The failure mode here is identical: a secret was treated as if it weren't secret.
What was taken, and should supporters be worried?
Beacon assessed that the criminals exported all data held in the database. Affected charities confirmed the stolen records can include supporter names, phone numbers and postal addresses.
Beacon doesn't store bank account numbers, sort codes or card details. Financial data sitting with payment processors elsewhere wasn't involved, and that genuinely limits the immediate harm.
The data was encrypted (scrambled to be unreadable), but Beacon acknowledged the attackers may have decrypted it before taking it. Treat your contact details as exposed.
If you've donated to or volunteered with a UK charity recently, watch for calls or emails that seem to know your name and charity involvement. That's exactly what fraudsters do with fresh contact lists. If something feels off, call the charity back on a number from their official website.
| Detail | What the investigation found |
|---|---|
| First malicious activity | 27 July 2025 |
| Data transfer window | 27 to 28 July 2025 |
| Entry method | Compromised AWS access key |
| Key exposure point | Public JavaScript build artifacts |
| Estimated scope | All data across the system |
| Customers affected | More than 1,000 charities |
No known criminal group has claimed responsibility. As of Beacon's latest update, the stolen data hasn't appeared online. The UK Charity Commission is monitoring and has issued guidance for affected organisations.
Should engineering teams be doing anything differently?
Yes, and they already know what. Rotate credentials on a short cycle, run secret-scanning tools (AWS has its own; so does GitHub) against every build artifact before it goes public, and treat any exposed key as fully compromised the moment it leaves your control. The hard part isn't knowing this. It's the ten minutes nobody found time for before the release went out.



