Beacon Breach Puts Gambling with Lives Records at Risk
The gambling harm charity became one of a growing number of UK organizations caught up in the incident at Beacon, a CRM platform used by charities and other non-profits. The breach dates back to late July, but new findings released this week give a clearer picture of how much data may have left Beacon’s systems.
Beacon Traces Access to an AWS Key
Beacon said the earliest malicious activity detected so far occurred on July 27 and lasted around 87 minutes. Its investigators believe a compromised Amazon Web Services access key was used to enter the system. The key may have been exposed through publicly accessible JavaScript build files.
Traffic records showed a sharp increase in data transfers on July 27 and 28. After comparing that activity with the volume stored on its systems, Beacon concluded that the attacker probably exported all data held in its database, including attachments.
The information was encrypted while stored in AWS. However, the attacker had valid credentials, meaning files downloaded through AWS would have been available in readable form. Beacon said it has found no evidence so far that the stolen information has been published or misused.
Gambling with Lives Reviews Exposed Records
Gambling with Lives told stakeholders about its involvement on August 6. The organization supports families affected by gambling-related suicides and uses Beacon as a third-party database provider.
According to the charity, affected records could contain names, addresses, contact information, dates of birth and donation history. Some entries may also include health or safeguarding information. Bank information was not among the data types it identified in the notice.
The organization said it was reviewing risks to individuals and warned recipients to be cautious about unexpected messages following the breach.
Charity Regulators Are Following the Case
Beacon has reported the incident to the Information Commissioner’s Office and said it has reset credentials linked to AWS, addressed the suspected vulnerability and introduced additional monitoring. It has not detected further unauthorized access since containment.
The Charity Commission is also monitoring the wider incident. On August 7, it urged affected charities to assess their reporting duties and decide whether people whose information was stored in Beacon need to be contacted. The regulator said it expects a significant number of serious incident reports linked to the breach.
Third-Party Data Risk Comes Into Focus
For Gambling with Lives, the main issue now is the type of information stored in individual records rather than the operation of its website or services. A CRM breach can expose data collected over years and from people who may already be vulnerable. The case also leaves charities with a supplier-risk question: sensitive records remain their responsibility even when the database itself is operated by an outside technology company.