See more Daily Mail on Google - save us as a Preferred SourceBy MILES DILWORTH and MARK NICOL, DEFENCE EDITOR Published: 18:25 BST, 19 August 2026 | Updated: 00:36 BST, 20 August 2026

One of the biggest ever cyber-attacks on the charity sector may have been trigged by a 'huge human error'.Up to 1,000 charities have been caught up in the hack, including Breast Cancer UK, English National Ballet and the Molly Rose Foundation.Criminals targeted Beacon CRM, which provides customer management software to the charity sector.It is thought the firm mistakenly published an access key online that allowed hackers to copy its databases.The blunder means millions of charity supporters may have seen their names and contact details stolen.Jake Moore, of cyber-security firm ESET, said it was 'a huge human error' – but Beacon has disagreed.Victims have been advised to change their passwords and be vigilant for scam emails or texts.Payment information has not been compromised, however – but security experts warned hackers would use stolen details to launch phishing attacks, armed with details of which charities victims have donated to. Up to 1,000 charities have been caught up in the hack, including Breast Cancer UK, National Ballet, Historic Buildings and Palaces, and the Molly Rose Foundation There are fears the elderly could be vulnerable as they are often generous donors.Beacon has 1,000 clients in the charity sector, including Girlguiding, Kidney Care UK, the British Deaf Association, various NHS and animal rescue charities and Blesma, an organisation that supports amputee veterans.It is not yet known how many have been affected, but millions could be at risk.Beacon has advised all its customers to assume that they may have been hacked.Historic Buildings and Places told members the stolen data may include 'your name, contact details, communication preferences, membership or donation history, Gift Aid records, event bookings, correspondence or notes relating to yourrelationship with us, and, for some individuals, gender and date of birth information'. English National Ballet and the Molly Rose Foundation, an online safety charity, issued similar statements.Beacon said it suspects it was hacked after an Amazon Web Services (AWS) access key was 'potentially exposed'. AWS provides data and cloud services to millions of customers.Alan Woodward, professor of cyber-security at Surrey University, said Beacon seemed to have published the key inadvertently as part of the code for its website.'It should not have happened,' he said. 'It's a cock-up, to use a technical term. Normally, there are automated tools that do security sweeps to make sure that sort of thing doesn't happen.'He added: 'It could be bigger than anything that has gone before [in the sector].'The Met's Cyber Crime Unit and the Information Commissioner's Office are investigating the breach, which occurred between July 27 and 31.A Beacon spokesman said it was 'swiftly contained', adding that the firm is 'committed to supporting' its customers as much as possible.