World

RNLI Warns Supporters After Hack at Outside Data Firm

Elena MarquezPublished 2d ago3 min readBased on 10 sources
Reading level
RNLI Warns Supporters After Hack at Outside Data Firm
source:rnli.org

The Royal National Lifeboat Institution has told supporters to assume personal information held for it was stolen by hackers. That includes names, contact details and records of contact with the charity. The Guardian

The warning came in a letter sent with the autumn issue of Lifeboat magazine. Lifeboat is the RNLI's supporter magazine with rescue stories, features, news and member offers. It includes a list of all lifeboat launches from the previous quarter.

The RNLI's own systems were not hacked. The break-in hit Beacon CRM, a company the charity uses to manage supporter records. CRM means customer relationship management, like a central filing cabinet for donations and messages. Beacon advised the RNLI to assume data in its systems was taken. The Guardian

The scope is large. About 1,500 charities were hit in late July. For the RNLI, the data is routine supporter information from donations and other contact. Its privacy materials say a donation creates personal data including the date and amount.

The RNLI said there is no evidence to date of misuse, sharing or publication of members' personal data. Beacon said in its report there was no evidence of a targeted attack on Beacon or any specific customer. The attacker told Beacon it would delete stolen data and retain, sell or share no copy. The RNLI states on its website it was made aware of a cyber security incident involving a third-party supplier holding supporters' data.

The warning comes as the charity also faces threats to volunteers. One volunteer faced online abuse after being wrongly identified as helping small-boat migrants reach land. BBC Police launched a probe after volunteers were called traitors and addresses were leaked online. The Independent That targeting followed anti-migrant protests.

Security experts warned RNLI members' identities could have been leaked or fallen into the wrong hands. The Telegraph The two risks are distinct. One is the bulk contractor theft. The other is deliberate identification of crew.

Chief executive Peter Sparkes addressed the Channel role separately in early September. On 8 September 2026, the charity published a video message from Sparkes on its Channel work and commitment to save lives.

It is not the first cyber disruption for the charity. In December 2021, the RNLI took its website down after a suspected hacking attempt with suspicious activity. The site was cut to a landing page. Threatening emails involving staff were reported in that episode.

The broader context here will be familiar to charity professionals. Donor-funded groups often keep supporter data with a few specialist suppliers, so one intrusion can touch hundreds of charities at once. An intruder's promise to delete data carries limited weight, and no evidence of misuse describes what is known so far, not a guarantee. For the RNLI, trust matters because crews depend on local goodwill and volunteers. If public discussion blurs the back-office breach with the separate leaking of volunteer addresses, confidence may suffer among supporters now asked to watch for phishing and fraud.