The Royal National Lifeboat Institution has written to supporters warning that their personal data may have been taken in a cyber attack on an external software supplier, in a letter sent out with the autumn issue of its Lifeboat magazine. The letter was first reported by The Sunday Telegraph on Sunday and has since been carried by the Guardian and LBC.
The warning concerns Beacon CRM, the customer relationship management provider the charity uses to hold supporter records. According to the Telegraph's account of the letter, supporters' "name, contact details and records of interactions with the RNLI" may have been affected, and the charity was advised by the provider to "assume that data held within its systems was taken".
The letter tells supporters: "At this stage we're not aware of any misuse of your personal information and have no evidence that your information has been published or shared."
The warning has reached the public a fortnight after RNLI volunteers in Portsmouth were abused and branded "traitors" for bringing about 120 people ashore at Eastney from a dinghy in the Channel on 6 September. The two events are separate. The Beacon intrusion was disclosed to the supplier's customers on 3 August, weeks before the Portsmouth rescue, and affected charities across the sector.
Beacon told customers in August that its early understanding was that access had been gained using stolen login details. A spokesperson said: "We are currently investigating the full circumstances of the incident with external cyber-security specialists, but our current understanding is that compromised credentials were used to gain access to Beacon." The company later said: "This was more sophisticated than a simple compromised username and password."
The supplier, which says it supports more than a thousand charities, reported itself to the Information Commissioner's Office and advised affected organisations to consider doing the same. In a report published this month, and cited by the Guardian, Beacon said there was no evidence of a targeted attack on the company or on any individual customer, and that the attacker had contacted it to say exfiltrated data would be deleted.
The Telegraph reported that unnamed online security experts had warned that the identities of RNLI members could have been leaked or fallen into the wrong hands. Those experts are not identified in the published account.
The RNLI has not said how many supporters received the letter, nor whether records relating to volunteers or crew, as opposed to donors, were held in the affected system. That distinction carries weight because volunteers have been the subject of online targeting since the Portsmouth rescue.
Portsmouth lifeboat station has been taken temporarily out of service. An RNLI spokesman said: "Given the unacceptable abuse our people have faced, and with protest activity taking place at RNLI locations, we have taken action to help ensure the safety and wellbeing of our volunteers and staff." The spokesman added: "We hope to have the lifeboat station back on service as soon as possible."
The charity's chief executive, Peter Sparkes, has described the abuse as "wholly unacceptable in a civilised society".
The Digital Secretary, Lisa Nandy, wrote to the RNLI on 14 September. "I was shocked and saddened to see RNLI staff and volunteers targeted during the unacceptable intimidation that took place during the weekend of 5-6 September in Portsmouth and Dover, both in-person and online," she wrote. "This behaviour is not acceptable and we will not tolerate it."
The RNLI says that of 9,058 lifeboat launches in 2025, 109 were to small boats in the Channel, or 1.2 per cent of its launches. The charity has reported a significant increase in fundraising since the protests.
One man, Del Somerville, 42, of Portsmouth, has admitted violent disorder in connection with the Eastney protest. He faces a further charge of assaulting a police officer, to which he has entered no plea, and was remanded in custody.
Join the Discussion
Have something to say? Join the conversation!
Sign in to share your thoughts and engage with other readers.
Sign In Create AccountNo comments yet
Be the first to share your thoughts on this article!