Skip to main content
BYMT logo small

Cyber-security incident affecting Beacon CRM

British Youth Music Theatre (BYMT) has been informed of a cyber-security incident affecting Beacon CRM (ISO 27001:2022 and Cyber Essentials Plus certified), a system we use to manage information about our participants, supporters and their involvement with us.

What happened?

Beacon informed us that an unauthorised person gained access to its systems and may have downloaded database backups containing information held by Beacon customers, including BYMT.

What information may be involved?

Depending on an individual’s relationship with BYMT, the information potentially affected may include:

  • Names and contact details
  • Dates of birth
  • Participation or donation histories
  • Emergency contact details
  • School or college information
  • Photographs
  • Information concerning access, disability or additional support requirements
  • Other information provided when registering for BYMT activities

The information held varies between individuals, and not everyone will have provided all these details.

Were payment details affected?

BYMT does not store full payment-card or bank account details in Beacon. Payments are processed separately through PayPal and GoCardless. Beacon has advised that there is no evidence that payment information held by these payment processors was compromised.

What has Beacon CRM done?

Beacon has implemented immediate measures to secure its systems and prevent any further unauthorised access. They are now:

  • Conducting a thorough forensic investigation with external cyber-security specialists to understand exactly what happened
  • Working with law enforcement and relevant regulators as required
  • Conducting online monitoring and so far, they haven’t seen anything of concern
  • Completing precautionary security measures
  • Assessing whether the incident is likely to result in a high risk to the rights and freedoms of individuals and, if so, will inform those concerned.

What have we done?

We have:

  • Informed all people with data records held in Beacon CRM
  • Reset passwords and enabled multi-factor authentication
  • Reviewed and restricted access to our Beacon account
  • Secured and reviewed connected services
  • Reported the incident to the Information Commissioner’s Office
  • Asked Beacon for further information about the affected records

We will continue to review our suppliers’ security and data protection arrangements to help ensure personal information is protected.

What should you do?

  • Please be particularly alert to unexpected emails, telephone calls or text messages claiming to be from BYMT or referring to your involvement with us.
  • Do not provide passwords, payment information or security codes in response to an unexpected communication. If you receive a suspicious message claiming to be from BYMT, please contact us using the details on our website rather than replying to it.
  • There is currently no evidence that your information has been misused. We will provide further information if this changes or Beacon’s investigation identifies any additional risks.
  • Please note that any bookings you have made via the BYMT website will be acknowledged with a confirmation email sent via Beacon. Please contact us if you have any concerns about a booking or payment you’ve made.

Contact us

If you have any questions or concerns, please contact mail@bymt.org.

We are sorry for the concern this incident may cause and are continuing to work with Beacon to understand and respond to it.