decrypted · 10 august 2026 · ransomware and cybercrime · uk policy and law · ai and llm security
The charity CRM breach that ran on one AWS key, and the 1,000 organisations behind it
Beacon, the customer relationship management platform used by more than 1,000 UK charities to manage donors and beneficiaries, has spent the past fortnight working out exactly what left its systems after an intruder got in on 29 July using a compromised AWS access key. The company notified customers on 3 August. Charities named as affected include Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice, the homelessness charity Clock Tower Sanctuary, and the victims' charity Victim Support. Nobody is calling this ransomware. It didn't need to be.
What went out the door
Beacon has told customers to assume that everything in their account, including attachment files, was downloaded: names, email addresses, phone numbers, donation histories and any documents charities had stored there. The data was encrypted, but Beacon's own investigators warned it could plausibly have been decrypted before it left, so charities cannot lean on encryption alone to avoid a breach notification. The Charity Commission and the ICO have both confirmed they are receiving serious incident reports and breach notifications from affected organisations, and have warned that the volume means responses will take longer than usual.
The lesson in the key
Beacon has been at pains to say this "was more sophisticated than a simple compromised username and password", and the distinction is the whole story. What was stolen was an access key: the kind of machine credential that lets one system talk to another without a human typing a password. Think of it less like a stolen door key and more like a courier's standing pass to a loading bay. It isn't challenged at reception, it doesn't expire at the end of a shift, and nobody necessarily notices when it is used to move an unusually large amount out in one go. Secure by Design treats machine credentials with the same discipline as human ones: scoped to the minimum they need, rotated on a schedule, and watched for anomalous use such as a bulk download of every customer's backups in a single sitting. Beacon has since reset the AWS credentials tied to the affected service, and is now telling the charities that use it to rotate their own API keys and integration tokens, since a supplier's fix does not automatically revoke keys a customer issued independently. For any UK organisation handing data to a CRM or SaaS supplier, the sharper question this week is not "do they encrypt our data" but "who holds the keys, and would anyone notice if all of it left at once".
Also this week
A baseline for energy, eventually. The Department for Energy Security and Net Zero and Ofgem published their response to the consultation on cyber regulation for downstream gas and electricity operators this week, confirming that Cyber Essentials Plus will become the foundation for new baseline cyber resilience requirements across all Ofgem licensees, developed with the NCSC. It is a sound Secure by Design instinct, a mandated floor rather than trust in self-assessment, but the timeline is generous: Ofgem will not consult on the detail until 2027, with full coverage targeted for the end of 2030. Energy operators would do well not to wait for the deadline before closing the gap CE+ will eventually require.
An AI tool with an open front door. CISA added CVE-2026-9198, a critical flaw in the open-source AI workflow builder Langflow, to its Known Exploited Vulnerabilities catalogue this week. The bug chains two API endpoints, one that hands out an administrator token to anyone who asks and one that will execute any Python code it is given, for full remote code execution on default installs. Telemetry has logged 650 exploitation attempts from 244 IP addresses since early July. It is fixed in version 1.10.1. Any UK team that has stood up Langflow for internal AI experimentation should check which version it is running before assuming this one is someone else's problem.
Sources
- Guidance for charities affected by the Beacon cyber security incident
- Beacon CRM cyber security incident: steps for charities to consider
- Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
- Commission issues guidance for charities after Beacon CRM data breach
- Reshaping cyber regulation in downstream gas and electricity: government response
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
If a supplier's breach has you rethinking who holds the keys to your data, get in touch.
More like this
- Revolut handed over customer data because an email looked official 15 september 2026
- The Windchill flaw PTC patched in June, and the extortion campaign that followed 25 july 2026
- The fake Claude app that lived on claude.ai, and the 29 firms it caught out 24 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.