Supporters of Yorkshire's Brain Tumour Charity were emailed on 12 August: an unauthorised third party had reached Beacon CRM, the database the Leeds charity uses, and exported all of it — names, addresses, donation records and health information. Beacon detected the intrusion on 29 July and warned customers on 4 August.
This isn't a YBTC problem. Beacon told every customer to assume all data stored in the platform has been downloaded. Sheffield Hospitals Charity was caught in the same incident. Beacon put the affected organizations at more than 1 000; later reporting puts it nearer 1 500 — close to its whole customer base. How many individuals, nobody knows.
The likely way in was an AWS access key exposed in publicly accessible JavaScript on Beacon's own site, embedded there by automated build tooling. Beacon says it has fixed the vulnerability, rotated its keys, forced password resets and added monitoring, and that no unauthorized access remains.
YBTC chief executive David Grant-Roberts says there's no evidence the data has been published, disclosed or otherwise misused, and asks supporters to be wary of unexpected emails, calls or texts mentioning YBTC, Beacon or donations. Affected charities have their own duty: report to the ICO within 72 hours, and the Charity Commission published guidance on 7 August.
Source: BBC News