A suspected “major human mistake” is believed to have set off what may become the largest cyber-attack ever to hit the UK charity sector.
As many as 1,000 charitable organisations are understood to have been affected by the data breach, with names including Breast Cancer UK, the National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation among those caught up in the incident.
The cyber-attack was aimed at Beacon CRM, a technology company that supplies customer relationship management software widely used by charities to manage supporter information.
According to early assessments, the breach may have stemmed from Beacon accidentally making an access key publicly available online, potentially giving hackers the ability to duplicate company databases.
The apparent security lapse could mean millions of charity donors and supporters have had personal details, including names and contact information, exposed in what cyber experts have described as an extraordinary “cock-up”.

As many as 1,000 charities are believed to have been affected by the hack, including Breast Cancer UK, the National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation
Jake Moore, a cyber security specialist at ESET, called the incident “a huge human error”.
Beacon, however, said it did not accept that characterisation of what happened.
Payment information has not been compromised. But security experts warned that hackers would use stolen details to launch sophisticated phishing attacks, armed with details of which charities victims have donated to.
Victims have been advised to change their passwords and be vigilant for scam emails or texts that could contain malicious links.
There are fears the elderly could be particularly vulnerable as they are often generous donors.
Beacon has 1,000 clients in the charity sector, including Girlguiding, Kidney Care UK, the British Deaf Association, various NHS and animal rescue charities, and Blesma, an organisation that supports amputee veterans.
It is not yet known how many were affected by the data breach.
But Beacon has advised all its customers to assume that they may have been hacked.
Historic Buildings and Places, formerly the Ancient Monuments Society, told members that the stolen data may include ‘your name, contact details, communication preferences, membership or donation history, Gift Aid records, event bookings, correspondence or notes relating to your relationship with us, and, for some individuals, gender and date of birth information’.
English National Ballet and the Molly Russell Foundation, an online safety charity, have also issued statements warning that names, addresses, contact details and donor records may have been stolen.
In an update, Beacon said it suspects it was hacked after an Amazon Web Services (AWS) access key was ‘potentially exposed’ online.
AWS provides data and cloud services to millions of customers worldwide.
Alan Woodward, professor of cyber-security at Surrey University, said it appeared as though Beacon had published the key inadvertently as part of the code for its website.
‘It should not have happened,’ he said. ‘It’s a cock-up, to use a technical term.’
He added: ‘Normally, before that kind of code is published, there are automated tools that do security sweeps to make sure that sort of thing doesn’t happen. But in this case, that clearly wasn’t done.’
Professor Woodward said the attack was significant because it hit one organisation ‘covering many charities at once’, creating a ‘force multiplier’ effect.
‘I’m not aware of anything that has hit [the sector] as hard as this,’ he added. ‘It could be bigger than anything that has gone before.’
Kevin Curran, professor of cyber security at Ulster University, said: ‘A lot of criminal organizations are increasingly targeting the IT manager because they know that they have the keys to the kingdom.’
He warned a ‘significant percentage’ of the stolen data ‘will belong to elderly people’ who are known to be ‘generous with charity’.

Kevin Curran, professor of cyber security at Ulster University, warned a ‘significant percentage’ of the stolen data ‘will belong to elderly people’
The Met’s Cyber Crime Unit and the Information Commissioner’s Office (ICO) are investigating the breach, which occurred between July 27 and July 31.
Beacon, which is based in London, was set up in 2017 to help charities with their databases.
It carries cyber-security certifications on its website, including a government-backed credential.
A spokesman said: ‘We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged the support of external cyber-security experts who swiftly contained the incident.
‘Data security is something we take incredibly seriously, and we recognise the impact this incident has had on our customers. We remain committed to supporting them as much as possible in any onward communication of their own regarding potential data impact.’