← LawCare

2026 LawCare — Beacon CRM supplier incident; callers/supporters/donors at risk (UK legal charity)

2026 Unknown records affected Share on X

Data compromised

LawCare uses Beacon for callers, supporters, donors, volunteers, and fundraising contacts. Charity advises assuming all Beacon-stored data and attachments may have been downloaded. Beacon records did not contain bank account numbers, sort codes, card numbers, or card security details per LawCare. Aggregate headcount not published — recordsAffected 0 pending census.

Technical writeup

Verified charity downstream notice — August 4–7, 2026. UK legal-sector mental-health charity LawCare confirmed it was affected by the Beacon CRM cyber-security incident affecting more than 1,500 UK charity customers. LawCare posted its first website statement on August 4, 2026, and updated through August 7 after Beacon’s investigation confirmed database backups were copied and likely downloaded; Beacon advised customers to assume all CRM data and attachment files may have been downloaded. LawCare uses Beacon to manage information about helpline callers, supporters, donors, volunteers, and fundraising contacts, and confirmed its Beacon records did not hold bank account numbers, sort codes, card numbers, or card security details. LawCare informed the ICO (case closed per charity update), reported no evidence of publication or misuse at indexing time, and urged vigilance against phishing impersonating LawCare. Canonical supplier incident: beacon-crm-backup2026. Aggregate individual count not published — recordsAffected 0.

Root cause

Downstream impact from Beacon CRM cyber-security incident (compromised access key; database backups copied and likely downloaded). LawCare first posted notice August 4, 2026.

References