Key facts
- RNLI supporters warned personal information may have been stolen by hackers.
- The breach occurred via Beacon CRM, a customer relationship management system.
- Names, contact details, and interaction records may have been accessed.
- The cyber-attack affected approximately 1,500 charities in late July.
- There is no evidence to date of misuse, sharing, or publication of the data.
- RNLI has faced targeting by far-right activists due to its work with Channel migrants.
Supporters of the Royal National Lifeboat Institution (RNLI) have been warned that their personal information may have been compromised in a cyber-attack targeting a third-party customer relationship management system. The charity stated in a letter accompanying its Lifeboat magazine that hackers may have accessed names, contact details, and records of interactions with the RNLI.
Beacon CRM, the company used by the RNLI for customer relationship management, advised the charity to "assume that data held within its systems was taken" following a cyber-attack in late July that affected approximately 1,500 charities. While there is currently no evidence of misuse, sharing, or publication of the stolen data, the breach comes amid increased targeting of the RNLI by far-right activists.
These activists object to the RNLI's involvement in rescuing people attempting to reach the UK on small boats. In response to protests and intimidation, including online and physical abuse directed at staff and volunteers, a lifeboat station in Portsmouth was temporarily shut. The RNLI reported a significant increase in donations following calls for people to stop donating.
The RNLI stressed that only 1.2% of its rescue operations last year, totaling 109 callouts out of 9,058, were related to small boats in the Channel. Beacon CRM stated that there was no evidence the attack was specifically targeted at them or any particular customer, and that the attacker indicated they would delete any exfiltrated data.