Skip to content Skip to footer

Encrypted at Rest, Readable on Exit: One Leaked Key Empties a Thousand Charity Databases

THE BIG DEAL Beacon, the customer relationship platform used by more than 1,000 UK charities, confirmed on 12 August that an attacker had copied its entire customer database and every attachment. The way in was an AWS access key left in JavaScript build artefacts on Beacon’s website. Encryption at rest made no difference: the stolen key was a valid credential, so the cloud handed over the backups in readable form across 27 and 28 July. Donors to rape crisis centres, hospital charities and victim support services are now in a stranger’s copy of the database. The ICO and the Charity Commission are involved, and each charity must notify its own supporters.

TAKEAWAY Encryption whose keys live beside the data protects against a lost disk and nothing else. Keep the keys in your own custody, separate from the platform, and scan every build and web asset for credentials before an attacker does.

PROTECT means the copied data stays encrypted, worthless to whoever holds it.

Subscribe to our newsletter and stay ahead of the breaches.

Download Data Risk Assessment Report..

Download Data Discovery Assessment Report..

Webinar

The Insider Threat You Can't Fire: Cybersecurity in Education.

Jun 24, 2026 12:00PM AEST