Data security incident involving Beacon CRM
Data security incident involving Beacon CRM
York Museums Trust has been informed of a security incident involving Beacon CRM, the customer relationship management (CRM) system we use to manage information relating to our patrons, donors, members and supporters.
This incident is not unique to York Museums Trust and affects organisations across the charitable sector that use Beacon CRM. We are sorry to be sharing this news. We understand this may be concerning, and we want to be open about what has happened, what information may have been involved and the steps we are taking in response.
What happened?
On 3 August 2026, Beacon CRM notified us that it had identified a security incident affecting customer accounts created before 27 July 2026.
Following notification, we immediately activated our incident response procedures and engaged our specialist data protection advisers, Evalian, to support our investigation and assess any risks.
We are continuing to work closely with Beacon CRM while they investigate the incident and implement any necessary security improvements.
What information may have been involved?
Based on the information currently available, some personal information held within Beacon CRM may have been involved. This could include:
- Name
- Email address
- Postal address (where provided)
- Telephone number (where provided)
- Communication preferences
- Membership information
- Event attendance records
- Donation history (amounts only)
We have no evidence that payment card details, bank account information, passwords or other sensitive financial information were affected.
What are the potential risks?
At this stage, the risk to individuals is considered to be low.
However, if contact information has been accessed, there is a possibility it could be used in phishing or scam attempts. This may include:
- Emails or messages claiming to come from trusted organisations.
- Telephone calls requesting personal information.
- Attempts to encourage you to click on fraudulent links or share sensitive information.
We have no evidence that any personal information has been misused as a result of this incident. However, we recommend remaining vigilant and taking extra care when responding to unexpected communications.
What actions has York Museums Trust taken?
We have taken the following steps in response to this incident:
- Activated our incident response procedures immediately after being notified.
- Engaged specialist data protection advisers, Evalian, to support our response.
- Reviewed the information held within Beacon CRM to assess the potential impact.
- Reported the incident to the Information Commissioner’s Office (ICO).
- Contacted individuals whose information may have been affected.
- Continued to work closely with Beacon CRM as they investigate the incident and implement appropriate security measures.
What should you do?
There is no action you need to take regarding payment cards or bank accounts, as we have no evidence that this information was affected.
As a precaution, we recommend that you:
- Be cautious of unexpected emails, text messages or phone calls.
- Do not share personal information unless you are confident you know who you are communicating with.
- Avoid clicking links or opening attachments in unexpected messages.
- Contact us if you receive any communication claiming to be from York Museums Trust that seems suspicious.
Further information
Protecting the personal information entrusted to us is extremely important. We are committed to being open and transparent throughout this process and will continue to provide updates if any new information becomes available.
If you have any questions or concerns, please contact us at communications@ymt.org.uk