14 August 2026
Chester Business Club is providing this notice to make our current and former members, event guests and wider CBC community aware of a cyber-security incident involving Beacon, the third-party CRM platform used by Chester Business Club to manage membership records, event bookings and associated administration.
Our current members have also been contacted directly regarding the incident. We are publishing this notice on our website to ensure that information is available to anyone who may have previously interacted with Chester Business Club through our membership or events.
What has happened?
Beacon recently identified unauthorised access to its systems and has been working with external cyber-security specialists to investigate the incident.
Beacon has now advised that a copy of the database containing its customer data, including attachment files, was made and was likely downloaded by the unauthorised third party.
Following analysis of data transfer activity, Beacon’s cyber-security specialists have assessed that the threat actor exported all data contained within the database.
Beacon has advised that it is unable to determine precisely which individual records were accessed or where the downloaded data was sent. Its investigation remains ongoing, with a final summary of its findings expected in the coming weeks.
This incident is not specific to Chester Business Club. Beacon is a third-party CRM platform used by a range of organisations, including clubs, charities and other businesses, and this incident affects Beacon’s wider customer environment.
What information does Chester Business Club hold in Beacon?
CBC uses Beacon to manage membership, subscriptions, events, ticketing and related administration.
The information held varies between individuals and records. Depending on the record, this may include names, addresses, email addresses, telephone numbers and business contact information, together with information relating to membership, events, tickets and transactions.
Importantly, CBC does not hold bank or card payment details in Beacon
We want to provide particular reassurance regarding financial information.
Chester Business Club does not store members’ bank account or card payment details within Beacon.
Membership and event payments are processed through separate external payment providers, including Stripe and GoCardless. Beacon may retain information relating to a transaction, such as the date, amount and payment source or method, but it does not hold the underlying card or bank account details used to make the payment.
There is also no indication at this stage that CBC data has been published or misused.
What does this mean for CBC?
CBC’s data is held within Beacon’s database and, as a result, we are treating the incident seriously.
While Beacon cannot identify which individual CBC records may have been accessed, its latest assessment means that we are proceeding on the basis that information held within our Beacon account may have been included in the data exported during the incident.
At present, we have no evidence that any CBC member, former member or event guest has experienced misuse of their personal information because of this incident.
The principal potential concern is the possibility of information being used for unsolicited contact. We therefore recommend remaining cautious about unexpected communications that appear to relate to Chester Business Club, membership, events or payments.
What action has CBC taken?
Chester Business Club has taken a number of steps in response to the incident, including:
- Reviewing the personal information held within our Beacon account and assessing the potential impact on the people whose information we hold.
- Reporting the potential personal data breach to the Information Commissioner’s Office (ICO).
- Communicating directly with our current members regarding the incident.
- Reviewing and strengthening our own internal security arrangements, including relevant login credentials and access controls.
- Continuing to liaise with Beacon and monitor information from its ongoing investigation.
Beacon has also confirmed that it has identified the likely cause of the unauthorised access, remediated the vulnerability, reset credentials associated with its AWS environment and introduced additional security monitoring. Beacon has advised that no ongoing unauthorised access has been identified since the incident was contained.
What should you do?
There is no specific action that CBC is asking members, former members or event guests to take at this stage.
However, as a sensible precaution, please remain vigilant for unexpected emails, telephone calls or messages that appear to come from Chester Business Club or relate to your membership, an event you have attended, a booking or a payment.
In particular, be cautious about requests for passwords, banking information, personal information or payments.
If you are unsure whether a communication genuinely comes from CBC, please contact us using our usual contact details rather than responding directly to the message.
What happens next?
Beacon’s investigation is still ongoing and it has advised customers that a final summary of its findings is expected in the coming weeks.
Chester Business Club will continue to review any further information provided by Beacon and assess whether any additional action is required.
We will update this notice if there are any material developments that affect CBC or the people whose information we hold.
We appreciate that any cyber-security incident involving personal information can be concerning. Our priority is to be open about what has happened, take appropriate steps to protect the information entrusted to us and keep our members and wider CBC community informed.
If you have any questions about this incident or the information Chester Business Club holds about you, please contact us at membership@chesterbusinessclub.co.uk.