AWS key exposed in JavaScript may have lit way to Beacon's charity data
A charity data breach occurred after an exposed AWS key in JavaScript allowed attackers to copy a CRM provider's customer database, which was likely downloaded in readable form.
A data breach at Beacon’s charity CRM provider was triggered by an exposed AWS key in JavaScript. The provider confirmed that a customer database was copied and likely downloaded in readable form. The exposed key allowed unauthorized access to AWS resources, potentially compromising sensitive charity donor information. The incident highlights risks of hardcoded cloud credentials in front-end code.