LawCare has revealed that copies of its database have been duplicated and are likely to have been downloaded by hackers. 

The organisation is one of more than 1,000 charities that use the software company Beacon CRM, which has been subject to a ‘cyber security incident’. 

Beacon is the system LawCare uses to manage information about callers, supporters, donors, volunteers and fundraising contacts. Details of any lawyer who has contacted LawCare may therefore have been stolen by an unauthorised third party. None of the records contain bank account numbers, sort codes, card numbers or card security details, the charity stressed. 

In a statement this afternoon, the legal charity said: ‘Beacon’s investigation into the incident, supported by external cyber security specialists, has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party. They recommend that we may want to assume that all data that we store in Beacon, including attachment files, have been downloaded.’

LawCare added: ‘We understand that this news may be worrying, and we are very sorry that information people have shared with us may have been affected.’

LawCare said there is no evidence that any of this information has been published or misused and the charity is not aware of any fraud or harm resulting from the incident. It said anyone who has been in touch with the service should be cautious about unexpected phone calls, messages, emails, links or requests for personal information, as contact details could potentially be used for phishing or other unsolicited communications.

LawCare informed the Information Commissioner’s Office following the breach. The ICO has confirmed that this particular case is now closed.

In 2025 alone 753 people were supported by LawCare, with 140 lawyers accessing its live online chat to seek help with mental health and wellbeing issues. This was the highest number of people who had ever contacted the charity in one year.

In a statement issued last week, Beacon said it had acted quickly to identify the threat and contain it, and the company is operating normally. Early investigations suggest that a compromised access key was used to gain access to the system, which was more sophisticated than a simply compromised username and password.

While Beacon stores data in an encrypted state, it is possible that the hackers were able to decrypt it.

Regulator the Charity Commission is actively monitoring the situation and urged affected charities affected to submit serious incident reports.

Anyone with questions or concerns is urged to email LawCare’s data protection officer on admin@lawcare.org.uk.