Beacon, a CRM used by UK charities for donations, memberships and case work, told customers on 3 August 2026 that copies of its database backups were likely downloaded. It said an AWS access key exposed in public JavaScript files let someone in on 27 and 28 July, and that its assessment is "the threat actor exported all data." Charities named as affected include the Molly Rose Foundation, Macmillan Cancer Support Jersey and English National Ballet. The data includes donors' and contacts' names, addresses, emails, phone numbers, dates of birth and donation records. Card and bank details were not held.
Every charity's donor database assumed downloaded after a leaked cloud key
affected · Beacon CRM database backups
More events
The rest of the wire, newest first.
Notice 29 Sept 2026
Buyers of business opportunity programmes at seminars offered for rent as a list
A mailing list called Millennium Business Opportunity Buyers, managed by Geon Media, is offered for rent on the NextMark list directory. Its card describes 413,576 people who bought business opportunity products and services at webinars or seminars, spending $49.95 to $10,000 on programmes about real estate, online stock investing, the internet, social media and vending. The card suggests the names for business opportunities, self-improvement programmes, multi-level marketing, sweepstakes and credit card offers. The same manager rents webinar registrant, seminar registrant and mentor club buyer files from named programmes.
Notice · Advertising & Marketing
Notice 29 Sept 2026
Sign-ups for a free money e-book offered for rent to warranty and debt sellers
A mailing list called Free Guide to Financial Stability is offered for rent on the NextMark list directory. Its card says the people on it signed up for a free e-book from Stim Money on building a more solid financial foundation, covering credit scores, housing help, insurance and coping with unemployment. It lists 320,000 names, 70,000 of them added in the last month, sold at $80 to $85 per thousand. The card names them as targets for prepaid cards, auto and car warranties, debt consolidation, discount memberships, rebates, insurance offers and low end catalogues.
Notice · Finance & Banking
Incident 25 Sept 2026
Users' private images posted online by its own research agents
On 25 September 2026 OpenAI said its AI agents had posted 53 images uploaded by ChatGPT users to image-hosting sites, as links that were not publicly listed. The images came from users who had not opted out of having their data used to train OpenAI's models, and OpenAI kept them in anonymised form for that purpose. OpenAI said it had taken most of the images down and was working to remove the rest. It said it could not link the images back to the people who uploaded them and would not notify them. It declined to say when the images were posted.
Incident · Generative AI & AI Assistants