First published at 3.33pm on 4 August 2026.
Last updated at 4.02pm on 12 August 2026.
Beacon have received a further update from their external cyber security experts which confirms their assessment that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format.
Please note that LawCare’s Beacon records do not contain bank account numbers, sort codes, card numbers, or card security details.
Beacon have updated their statement with relevant information here: https://www.beaconcrm.org/incident
We understand that this news may be worrying, and we are very sorry that information people have shared with us may have been affected.
We have emailed everyone whose email address we hold in Beacon to let them know about the incident.
We informed the Information Commissioner’s Office (ICO) of the incident. They have responded and confirmed that the LawCare case is now closed. We have also notified the Charity Commission.
Beacon CRM is used by over 1,000 charities and is a trusted and reputable company. It is certified for ISO 27001:2022, the leading global standard for information security, and also holds Cyber Essentials Plus Certification.
Although this wasn’t an issue caused by LawCare, we’ve taken the opportunity to review our Data Protection Impact Assessment (DPIA), Record of Processing Activities (ROPA) and business continuity plan, and we’re satisfied that the measures we have in place are robust.
There is currently no evidence that any of this information has been published or misused and LawCare is not aware of any fraud or harm resulting from this incident.
Anyone who has been in touch with LawCare should be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.
Please be particularly alert to any communication that appears to be from LawCare. If you are unsure whether a message is genuine, please contact us directly using our email address and we can confirm whether it has come from us.
Remember, never share passwords, bank details or security codes in response to a request. Always check the sender’s email address carefully before replying or clicking on any links and keep an eye on your accounts for any signs of suspected fraud.
Anyone with questions or concerns should email LawCare’s data protection officer (Emma Manley) on [email protected].
Trish McLellan (Interim CEO) and Emma Williams (Chair of Trustees)
LawCare
Further information
Latest statement from Beacon: https://www.beaconcrm.org/incident