We have been made aware of a cyber security incident involving Beacon, the external customer relationship management (CRM) provider used by Youth Theatre Arts Scotland.
The incident may have involved some of the personal information we hold about our members. As YTAS take the security of your information seriously, we want to explain what we currently know, what is being done and has already been done by both ourselves and Beacon, and how you can protect yourself.
We expect that there will be very low risk of any impact on our members as a result of this incident as there is very little information stored in this system beyond names, email addresses, event attendances, and membership status. Members should be reassured that your YTAS website login credentials, membership tiers, and more importantly, card details connected to membership payments, are processed separately and not stored within the Beacon system.
What happened
On Wednesday 29 July 2026, Beacon became aware that it may have experienced a cyber security incident in which an unauthorised third party gained access to its systems. Beacon acted quickly to identify the likely cause of the unauthorised access, engaging external cyber security experts to help investigate and secure its systems.
Beacon’s current understanding is that compromised credentials were used to gain access to its system, copies of its database backups were made and, based on the evidence currently available, were likely downloaded.
As a result, personal information held by YTAS within Beacon may have been accessed.
What is being done by Beacon
Beacon has told us that it has taken immediate measures to secure its systems and prevent further unauthorised access. It is conducting a forensic investigation with external cyber security specialists to understand exactly what happened, and is continuing to work with them to ensure it does not happen again. Beacon is also conducting online monitoring, as is standard practice in these kinds of incidents. So far, it hasn’t seen anything of concern. Beacon’s investigation is continuing and YTAS will be updated if Beacon learns anything significant that changes this assessment.
The impact on YTAS and what we’ve done
YTAS has assessed the potential risks to the people whose information we hold, while taking appropriate steps to protect our systems and information. Keeping your data secure is of utmost importance to YTAS, and we are reassured that Beacon have taken this incident very seriously.
We expect that there will be very low risk of any impact on our members as a result of this incident. Beacon is a new part of the system that is used to facilitate memberships at YTAS, but is not yet being used to its full capacity, as we have only very recently implemented changes to our membership scheme. As such, there is very little information stored in this system beyond names, email addresses, event attendances, and membership status.
Card details connected to membership payments are not stored within the Beacon system. The only times YTAS collects payment through Beacon is for event sign-ups and upgrades related to recent events, such as Knowledge Exchanges, Bid Clinics, and Regional Hubs. However, Beacon say there is no evidence that any card details have been compromised, and that it is safe for us to continue to collect payments in this way.
YTAS have also followed all of Beacon’s recommendations regarding password and 2FA credential resets, and have reconnected all API keys.
What you can do
In spite of what we have assessed to be a low risk, we would still advise our members to remain alert to suspicious emails, telephone calls, text messages, or social media approaches that appear to come from YTAS or refer to your relationship with us. We are not currently aware of any misuse of the information, but precautions are recommended because criminals sometimes use personal contact information to appear convincing.
In particular…
- be cautious about unexpected requests for money, passwords, banking information, or security codes.
- do not open unexpected attachments or follow suspicious links.
- check requests by contacting us through the telephone number or email address on our website, not by using contact details supplied in a suspicious message.
- please tell us promptly if you receive a suspicious communication that appears to relate to YTAS.
Questions or Concerns
We are very sorry for the concern this incident may cause. If you have any questions or concerns, please don’t hesitate to contact our team. We are here to help and will be happy to discuss this with you.
