Local Government Lawyer

LawCare said the data leak was the result of an attack on a customer relationship management system known as Beacon used by the charity.

According to Beacon, the cyber-security incident involved unauthorised access to the system, which manages information about LawCare's callers, supporters, donors, volunteers and fundraising contacts.

The supplier said that its investigation into the incident, supported by external cyber security specialists, confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party.

It said that charity should assume that all data stored in Beacon, including attachment files, has been downloaded.

Commenting on the security breach, LawCare said: "We understand that this news may be worrying, and we are very sorry that information people have shared with us may have been affected.

“We [LawCare] informed the Information Commissioner’s Office (ICO) of the incident. They have responded and confirmed that the LawCare case is now closed.

“Beacon CRM is used by over 1,000 charities and is a trusted and reputable company. It is certified for ISO 27001:2022, the leading global standard for information security, and also holds Cyber Essentials Plus Certification."

LawCare has since carried out a review of its Data Protection Impact Assessment (DPIA), Record of Processing Activities (ROPA) and business continuity plan, despite not being responsible for the breach.

"We’re satisfied that the measures we have in place are robust," it said.

The charity said there is no evidence that any information has been published or misused, but said that anyone who has been in touch with LawCare should be cautious about unexpected phone calls, messages, emails, links or requests for personal information.

Adam Carey

Newsletter signup