Summary
- Beacon now assesses that a copy of the database holding its customer data, including attachments, was made during the incident.
- Band of Builders says its records may have been included and that some contain particularly sensitive medical or financial information.
- Customers must make their own data-protection and governance decisions while the supplier investigation continues.
The consequences of the Beacon CRM breach are becoming more specific for UK charities, with construction-sector charity Band of Builders confirming that records potentially included in the copied data contain medical and financial information.
Beacon is used as a customer relationship management platform by charities and other organisations. The incident was first disclosed earlier this month, when investigation indicated that unauthorised access had been used to obtain customer database material.
Band of Builders has now said Beacon confirmed its assessment that a copy was made of the database holding all Beacon customer data, including attachment files. Information from the charity’s own database may have been included.
The charity is contacting individuals whose records may contain particularly sensitive information, including medical or financial details, and has reported the incident to the Information Commissioner’s Office.
Band of Builders’ disclosure adds a category of exposure that was not established when the Beacon incident first emerged. A common CRM platform can hold very different information for each customer, leaving the consequences of the same supplier breach dependent on the records each organisation placed in the service.
Within the charity sector, CRM systems can extend well beyond ordinary donor contact information. Depending on the organisation, they may contain beneficiary assessments, support requests, medical context, hardship records, financial circumstances, and supporting documents alongside routine fundraising data.
The Charity Commission is monitoring the incident and working with the ICO. Affected charities may have separate reporting and governance duties even though the initiating compromise occurred at a technology provider rather than within their own infrastructure.
That structure creates parallel incident-response work. Beacon must establish what occurred across its platform, while each customer has to determine which of its records were present, how sensitive those records were, who may be affected, and whether regulatory, contractual, or safeguarding obligations arise.
Accurate data inventories become particularly valuable once an outsourced platform is compromised. Knowing that a supplier processes personal data is not the same as knowing which attachments, historical records, special-category information, or locally defined fields were present at a particular point in time.
Supplier assurances and security certifications can reduce risk, but neither removes the customer’s need to understand what information it has entrusted to the service. Once an incident occurs, the speed of downstream assessment depends heavily on whether that exposure can be reconstructed without waiting for the provider to complete every part of its forensic investigation.
Band of Builders’ latest incident update does not state that its sensitive records have been published or misused. Its position is narrower: its information may have been included in the copied Beacon database, and individuals whose records may contain particularly sensitive material are being contacted.
A copied database represents loss of control over information, but it does not establish what has subsequently happened to every record. The current operational burden nevertheless falls across numerous independent charities, each making its own notification, governance, and communications decisions from one upstream supplier incident.




