SecBriefs
← All briefs

An AWS key exposed in JavaScript was linked to data from 1,500 UK charities

A secret embedded in client-side code can turn one mistake into access across many organizations.

Hand-drawn SecBriefs editorial illustration: An AWS key exposed in JavaScript was linked to data from 1,500 UK charitiesSOURCE · The Register
© 2026 SecBriefs · Original illustration

THE BRIEF

Researchers linked an AWS access key exposed in publicly delivered JavaScript to a data incident affecting information associated with more than 1,500 UK charities.

WHY IT MATTERS

Cloud keys are credentials, even when they look like configuration. A shared service can magnify one exposed secret across many customers and datasets.

WHO SHOULD CARE

Cloud developers, charities, SaaS providers and teams responsible for secret management.

WHAT TO DO NOW

  • Revoke and rotate exposed keys immediately.
  • Search code, build artifacts and history for copied secrets.
  • Use short-lived identities and server-side access instead of browser-delivered keys.

VERIFICATION NOTE

Source basis: The Register reporting. The affected organizations and exact data categories may vary.

Read original at The Register

SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.