- September Edition
- Reading time~ 2mins
THE BIG DEAL Beacon, the customer relationship platform used by more than 1,000 UK charities, confirmed on 12 August that an attacker had copied its entire customer database and every attachment. The way in was an AWS access key left in JavaScript build artefacts on Beacon’s website. Encryption at rest made no difference: the stolen key was a valid credential, so the cloud handed over the backups in readable form across 27 and 28 July. Donors to rape crisis centres, hospital charities and victim support services are now in a stranger’s copy of the database. The ICO and the Charity Commission are involved, and each charity must notify its own supporters.
TAKEAWAY Encryption whose keys live beside the data protects against a lost disk and nothing else. Keep the keys in your own custody, separate from the platform, and scan every build and web asset for credentials before an attacker does.
PROTECT means the copied data stays encrypted, worthless to whoever holds it.
Related Blogs
Eight Agents, Four Days: AI Runs a Government Intrusion in Taiwan
Closer to Home: Origin Energy’s Breach Traced to a Manila Call Centre
284 Million Rows in Four Days: McKesson’s Cloud Warehouses Emptied
How an SME Built a Security Posture That Enterprise Clients Trust
What If Your Data Could Protect Itself? A Data-First Security Playbook
Payment Security Summit & Gala – Australia 2026
Do you know where your sensitive data is?
Stop your IP and Design files from being stolen?


