teiss – News – UK charity LawCare warns members after data breach at CRM supplier Beacon
ao link
UK charity LawCare warns members after data breach at CRM supplier Beacon
LawCare, a United Kingdom charity that provides mental health and wellbeing support for the legal sector, has warned people on its database to remain vigilant following a cyberattack on Beacon CRM, a customer relationship management software provider used by more than 1,000 charities and nonprofit organizations.
The charity first disclosed the breach on August 4 in a statement on its website, which it has continued to update as additional details emerge. It has also emailed people in its database with information about the incident and guidance on responding to suspicious communications.
In that email, interim Chief Executive Trish McLellan and Board of Trustees Chair Emma Williams said Beacon CRM had told LawCare it “may want to assume that all data that we store in Beacon, including attachment files, have been downloaded.” McLellan and Williams wrote, “We understand that this news may be worrying and we are very sorry that information you have shared with us may have been affected.”
LawCare relies on Beacon CRM to manage information related to its callers, supporters, donors, volunteers and fundraising contacts. The charity confirmed the data held in Beacon did not include bank account numbers, sort codes, card numbers or card security details.
McLellan and Williams cautioned recipients to watch for unexpected phone calls, messages, emails, links or requests for personal information, noting that contact details could be used for phishing or other unsolicited communications, and urged particular alertness toward any message appearing to come from LawCare. Anyone uncertain whether a communication is genuine was advised to contact the charity at admin@lawcare.org.uk.
According to the latest update on LawCare’s website, there is no current evidence that the affected information has been published or misused, and the charity says it is not aware of any resulting fraud or harm. The organization said it used the incident as an opportunity to review its Data Protection Impact Assessment, Record of Processing Activities and business continuity plan, and stated it is satisfied that its existing safeguards are robust. LawCare also reported the incident to the Information Commissioner’s Office, which has since closed the case.
A LawCare spokesperson said staff have been meeting daily to share updates and coordinate the charity’s response, and that LawCare intends to report the incident to the Charity Commission and the Office of the Scottish Charity Regulator.
Beacon CRM addressed the incident in a customer update issued August 4, describing it as a cybersecurity incident. The company said its investigation had confirmed that copies of database backups were made and likely downloaded by an unauthorized third party, and that it had identified a spike in system activity consistent with data leaving its systems during the relevant timeframe. Beacon said it was unlikely to be able to determine more precise details about which data was affected or whose information was involved, and advised customers to assume, out of caution, that all data stored in Beacon, including attachment files, had been downloaded.
LawCare is among the UK legal sector’s most prominent charities, offering confidential mental health and wellbeing support to people working in law across the UK, the Channel Islands and the Isle of Man through a helpline, live webchat and email service.
Please take 30 seconds to register
Already have an account? Sign in
