Several UK cultural organisations are dealing with the fallout from a cyber-security incident at technology firm Beacon.
Museums including the Foundling Museum in London, the National Videogame Museum in Sheffield, the York Museums Trust and the English National Ballet were among the arts institutions affected.
Beacon, a company that provides customer relationship management (CRM) systems to charities, notified those affected by the issue on 3rd August, leading many organisations to email their customers alerting them to the problem.
The incident follows a number of similar cyber attacks on UK cultural institutions in recent years, including the British Library in 2023 and the National Museum of the Royal Navy in 2024.
A Beacon spokesperson said: "We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers. We immediately engaged external cyber-security experts to help us contain the incident and investigate.
"We understand this is concerning and we’re taking it very seriously. We’ve already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact.
"Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal."
More than 1,000 charities currently use Beacon services.
The Charity Commission has said they're aware of the incidents and are in contact with the Information Commissioner's Office (ICO). They have encouraged trustees to consult official guidance for charities on dealing with cyber crime as well as reporting obligations to other regulators, such as the ICO, and to individuals whose data is stored on Beacon systems.
