Skip to main content

Beacon CRM security incident

News

We have been informed that Beacon CRM (customer relationship management), used by LawCare to manage information about our callers, supporters, donors, volunteers and fundraising contacts, has experienced a cyber-security incident involving unauthorised access to its systems.

Hands typing on a laptop keyboard

Last updated at 9.51am on 5 August 2026

Beacon’s investigation into the incident has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party. They recommend that we may want to assume that all data that we store in Beacon, including attachment files, have been downloaded.

Please note that LawCare’s Beacon records do not contain bank account numbers, sort codes, card numbers, or card security details.

Beacon will be updating their statement with relevant information as their investigation progresses. Read their latest update here: https://www.beaconcrm.org/incident

We understand that this news may be worrying, and we are very sorry that information people have shared with us may have been affected.

We [LawCare] have informed the Information Commissioner’s Office (ICO) of the incident.

Beacon CRM is used by over 1500 charities and is a trusted and reputable company. Beacon is investigating the incident with external cyber-security specialists.

Although this wasn’t an issue caused by LawCare, we’ve taken the opportunity to review our Data Protection Impact Assessment (DPIA), Record of Processing Activities (ROPA) and business continuity plan, and we’re satisfied that the measures we have in place are robust. 

There is currently no evidence that any of this information has been published or misused and LawCare is not aware of any fraud or harm resulting from this incident.

Anyone who has been in touch with LawCare should be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.

Please be particularly alert to any communication that appears to be from LawCare. If you are unsure whether a message is genuine, please contact us directly using our email address and we can confirm whether it has come from us.

Remember, never share passwords, bank details or security codes in response to a request. Always check the sender’s email address carefully before replying or clicking on any links and keep an eye on your accounts for any signs of suspected fraud.

Anyone with questions or concerns should email LawCare’s data protection officer (Emma Manley) on [email protected].

Trish McLellan (Interim CEO) and Emma Williams (Chair of Trustees)

LawCare

Further information

Latest statement from Beacon: https://www.beaconcrm.org/incident

Free, confidential support
0800 279 6888