Skip to content
theregister·

🚨Beacon Data Breach Exposes Customer Databases and AWS Keys

Charities hit hard by Beacon's data breach

TL;DR

Beacon's recent security incident exposed AWS access keys and possibly customer databases. Over 1,500 charities may have been affected, with personal information at risk.

Beacon experienced a significant data breach that potentially exposed AWS access keys in public JavaScript build artifacts and compromised its customer database containing over 1,500 charity records. This incident highlights the importance of robust security measures for cloud-based systems, especially those handling sensitive data from non-profits. The malicious activity lasted one hour and 27 minutes on July 27-28, with a significant spike in AWS data transfer costs during this period. While encryption at rest was enabled, the compromised keys may have allowed access to encrypted data.

Beacon Data Breach Exposes Customer Databases and AWS Keys — theregister

Key Points

1

AWS access key exposure in public JavaScript build artifacts led to potential database compromise on July 27-28.

2

Over 1,500 charity records were at risk due to compromised AWS keys and possible data exfiltration.

3

Data transfer costs spiked significantly during the breach window of one hour and 27 minutes on July 27-28.

4

The Charity Commission prioritizes incident reports from affected charities like Molly Rose Foundation and Macmillan Cancer Support Jersey.

5

Beacon advises customers to review their CRM instances for potential exposure, but specific impact remains unclear.

Why It Matters

If you're managing sensitive data in the cloud, especially for non-profits or charities, this breach highlights critical security gaps. Over 1,500 charity records were potentially compromised, emphasizing the need for robust access controls and continuous monitoring. The incident underscores that even encrypted data can be at risk if keys are exposed.

AWSdata-breachcharitiescloud-encryption

Frequently Asked Questions

Why does this matter?

If you're managing sensitive data in the cloud, especially for non-profits or charities, this breach highlights critical security gaps. Over 1,500 charity records were potentially compromised, emphasizing the need for robust access controls and continuous monitoring. The incident underscores that even encrypted data can be at risk if keys are exposed.

What happened?

Beacon's recent security incident exposed AWS access keys and possibly customer databases. Over 1,500 charities may have been affected, with personal information at risk.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,003 builders reading daily.

Also get