Exposed AWS Key Leaks Data from 1500 UK Charities – Veri Sızıntısı

Exposed AWS Key Hits 1500 UK Charities in Data Breach

Data from over 1500 UK-based charities was leaked following a cyber-attack on CRM provider Beacon. The root cause of the attack is believed to be an AWS access key exposed in public software build files.

A broken padlock icon in front of buildings representing charitable organizations

What Happened

A large-scale data breach has struck the UK charity sector. Customer Relationship Management (CRM) software provider Beacon confirmed it suffered a cyber-attack that affected its entire customer base of over 1500 charities. According to a statement on August 12, attackers infiltrated the company's cloud infrastructure and gained access to all data managed by these organizations.

The incident stands out as a typical example of a supply chain attack. While the charities themselves were not the direct targets, a vulnerability in a central software platform they all use left thousands of organizations simultaneously vulnerable. Beacon offers a CRM platform specifically designed for non-profit organizations. These platforms house critical operational data, including donor management, volunteer tracking, event organization, and records of service beneficiaries. Consequently, the compromise of this system means that the most sensitive information of these charities has also been exposed.

What Data Was Leaked

According to Beacon's statement, the attackers managed to download "all data" contained within the CRM platform. This includes not only standard contact information but also any attachment files uploaded to the system. This significantly increases the scope and potential impact of the breach.

The nature of the leaked data is particularly concerning given the fields in which the affected organizations operate. Beacon's client portfolio includes institutions working in highly sensitive areas, such as healthcare providers and victim support groups. The personal data held by such organizations can include the identities of vulnerable individuals, their health conditions, traumas they have experienced, and details of the support services they have received.

Technically, the data was encrypted "at rest" on Amazon Web Services (AWS). However, because the attackers obtained a valid access key, they were recognized as authorized users by the AWS systems. Therefore, when they downloaded the data, the system automatically decrypted it, presenting it to the attackers in a readable format. This incident once again demonstrates that at-rest encryption alone is not sufficient, and that access management and key security are critically important.

How Did the Attack Happen

The root cause of the attack appears to be a fundamental security oversight. According to Beacon's initial analysis, the AWS access key used by the attackers was potentially exposed in public JavaScript "build artifacts." This points to an error made during the software development and deployment process.

During the build process, developers can accidentally include sensitive information, such as API keys or access tokens, within configuration files or code snippets. If these output artifacts are later uploaded to a public code repository or web server, attackers can scan these areas to easily find such valuable credentials.

Beacon's review of its AWS Cost & Usage reports clarified the timeline of the attack. Malicious activity began on July 27 at 01:20:16 UTC and lasted for approximately 1 hour and 27 minutes. This short duration suggests that the attackers used automated tools to exfiltrate the data quickly. The company noted that this time frame correlates with an anomalous spike in data download metrics on July 27-28.

After detecting the incident, Beacon stated that it found no evidence of the attacker attempting to maintain persistence within its environment. As a precaution, all credentials for services and accounts integrated with AWS were reset. This is intended to prevent the same key or other compromised credentials from being used for future unauthorized access.

Who Is Affected

Those directly affected by the attack are the more than 1500 UK-based charities and non-profit organizations that use Beacon's CRM platform. These organizations manage a wide range of data, from their donors and volunteers to the individuals they serve.

One of the affected institutions, The Survivor's Trust, publicly announced on August 13 that it was impacted by the breach. The organization, which provides support to victims of violence, stated that it had immediately reported the situation to the UK's data protection authority, the Information Commissioner's Office (ICO). The statement noted that the ICO had reviewed its case and did not hold the charity responsible for the breach. This decision indicates that the responsibility for the data breach lies with the software provider, Beacon, which was expected to have the necessary security measures in place.

Beacon has advised all its customers to report the data breach to the ICO. There has been no evidence so far that the stolen data has been published online or otherwise misused. However, the risk remains that such data could be used in the future for phishing attacks, fraud, or blackmail.

What You Can Do

This breach concerns multiple stakeholders, and there are different steps each group should take:

  • Affected Charities: If your organization is a Beacon customer, you should carefully follow the guidance provided by the company. You must report the incident to the ICO immediately and transparently inform your own stakeholders (donors, volunteers, beneficiaries) about the risks. It is critical to scrutinize cybersecurity standards and audit reports more thoroughly when selecting vendors in the future.
  • Donors and Volunteers: If you have recently donated to or volunteered for charities in the UK, be aware that your personal data may have been compromised. Be particularly suspicious of emails and messages that appear to come from these organizations. Never respond to requests for passwords, financial information, or personal details.
  • Other Organizations and Developers: This incident highlights how vital security controls are within the Software Development Life Cycle (SDLC). Use automated scanning tools to prevent sensitive information (access keys, passwords, API tokens) from being committed to code repositories and public files. Train your developers on secrets management and regularly audit and rotate access keys in your cloud infrastructure.

What the Company Says

In its incident update on August 12, Beacon adopted a transparent stance. The company acknowledged that the likely root cause of the attack was an AWS access key exposed in public JavaScript files. They implied that an error in the software development process led to this situation.

The statement confirmed that the attacker used these valid credentials to access and download all data and attachment files from the CRM platform, thereby impacting the entire customer base. The company emphasized that the attackers did not attempt to establish persistence in the system and that all credentials were reset following the incident. They also added that there has been no indication so far that the stolen data has been published online or otherwise misused.

Source

https://www.infosecurity-magazine.com/news/exposed-aws-key-data-charities/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.