One exposed key at a software supplier put its entire customer database in the wrong hands
Cyber Security

One exposed key at a software supplier put its entire customer database in the wrong hands

Beacon's CRM holds records for more than 1,500 UK charities. An AWS key left sitting in public build files is the likely way in.

14 August 20264 min read

Beacon makes CRM software used by more than 1,500 UK charities. In an update reported on 13 August, the company confirmed that a copy of the database holding all Beacon customer data, attachment files included, was made and likely downloaded in readable form. It has not established how many of its customers had data taken. The organisations now writing to their supporters did not misconfigure anything. Their supplier did.

What happened

Beacon's chief technology officer, David Simpson, said an AWS access key had been potentially exposed in public JavaScript build artefacts, which in plain terms means a working credential was left in files anyone could fetch off the internet. The malicious activity began in the early hours of 27 July and ran for one hour and 27 minutes. Amazon's own cost and usage reporting showed a large data transfer across 27 and 28 July, which is how the scale was pinned down. Simpson has also said there are things about the incident that may never be established.

Encryption at rest did not help

The data was encrypted while it sat in AWS. That made no difference, because the attacker held a valid key, so AWS decrypted the files on the way out exactly as it would for a legitimate request. Encryption at rest protects you against somebody walking off with the hardware. It does nothing about somebody holding a working credential. Worth remembering the next time a supplier's security page offers encryption as the whole answer.

What was taken, and what was not

The records included supporters' names, email addresses, telephone numbers and donation histories. Beacon has said the system did not hold payment card details, bank account details or patient data. Organisations named as caught up in it include Macmillan Cancer Support Jersey, English National Ballet and the British Deaf Association. The Charity Commission has confirmed it has received a number of serious incident reports and is working through the volume. The Survivor's Trust, one of those affected, has said the Information Commissioner's Office concluded the charity itself bore no responsibility for the breach.

The question this raises for any business

Swap charity for accountancy practice, letting agent or builders' merchant and nothing about the shape of it changes. Customer lists, contact details and transaction history sit in cloud systems your business does not run and cannot inspect. When the supplier gets it wrong, you are still the one telling your customers, and you are the one they judge for it. Most firms cannot name every system holding their customer data, never mind say how quickly they would hear if one of them was breached.

What to do about it

Write down which suppliers hold personal data on your behalf, what each one holds and who your named contact is there. Check what the contract says about breach notification and how fast that notification has to come. Ask whether the supplier holds Cyber Essentials or an equivalent, and whether the certificate is current rather than something they earned three years ago. Then decide in advance what you would say to customers, because the day you need those words is the day you have least time to find them.

What this means for your business

Your data protection duties do not travel with your data. If a supplier loses it, the letter to your customers still carries your name. Spend an hour listing every system outside your own walls that holds customer information, check what each contract actually promises about telling you when something goes wrong, and give someone ownership of that list. Cyber Essentials is a sensible baseline to expect from anyone handling your customer records, and asking a supplier for it is a fair question rather than an awkward one.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.