Cookie Consent by Free Privacy Policy Generator

Exposed AWS access key leads to data breach affecting over 1500 UK charities

UK charity CRM provider Beacon has confirmed that a compromised AWS access key was the root cause of a data breach affecting more than 1500 UK charities. Infosecurity Magazine reports that the exposed credential allowed unauthorised access to systems containing donor information, contact details and operational data held by Beacon on behalf of its charity clients. The breach was identified after unusual activity was detected, and Beacon has since revoked the compromised key, implemented additional monitoring and notified affected organisations. The incident is a reminder that cloud security depends on consistent credential management, access controls and monitoring, particularly for platforms that hold data on behalf of multiple clients.

Why this matters for UK organisations

This breach highlights the operational risk created when cloud credentials are not managed with the same discipline as on-premise systems. AWS access keys, API tokens and service account credentials are often stored in configuration files, shared across teams or embedded in scripts, creating multiple opportunities for exposure. When a single credential is compromised, the impact can extend across many organisations, particularly in managed service or SaaS environments where one provider holds data for hundreds or thousands of clients. This incident is especially relevant for charities, membership organisations, professional bodies and other sectors that rely on third-party CRM, fundraising or membership platforms to manage sensitive personal data. It also raises questions about supply chain risk, third-party due diligence and the extent to which organisations understand how their data is protected by the platforms they depend on.

What to review

Organisations should review how cloud credentials are managed, stored and monitored, particularly for AWS, Azure and other cloud platforms. Access keys should be rotated regularly, permissions should follow the principle of least privilege, and monitoring should be in place to detect unusual API activity or access patterns. For organisations using third-party SaaS or managed service providers, this is also a reminder to ask suppliers about their credential management practices, access controls and incident detection capabilities as part of due diligence and contract reviews. Organisations should also consider whether they have visibility into how their data is stored, who has access to it, and what controls are in place to detect and respond to unauthorised access. This is a practical governance question that should be addressed before incidents happen, not after.

Source: Infosecurity Magazine

News and blog posts
The National Cyber Security Centre has published new guidance recommending that...
UK charity CRM provider Beacon has confirmed that a compromised AWS access key...
Security researchers have identified a global exploitation campaign targeting...
The North Korean threat actor known as Lazarus Group has been linked to the...