Donate now

RNLI affected by Beacon CRM cyber security incident

Our statement and information for supporters

On Monday 3 August, Beacon CRM informed the RNLI it was investigating a cyber security incident affecting its systems. Beacon CRM is a third-party that we were working with to provide a new supporter database. 

We are working closely with Beacon CRM and independent specialists to understand exactly what this means, and how the RNLI might be affected. 

We understand this will be concerning for our supporters, volunteers and partners, and we sincerely apologise for any worry this may cause. Protecting your personal information is extremely important to us. 

At this stage, Beacon CRM has not confirmed whether any RNLI data has been accessed, but has advised all its customers to assume, as a precaution, that data stored within its systems may have been involved while investigations continue.

These investigations are ongoing. If we find that any of our supporters need to be notified about the data involved, we will make direct contact at the earliest opportunity to explain what this means and provide the support they need.

We are committed to being open and transparent as the situation develops and will provide further updates when more information becomes available.

In the meantime, if you have any questions or concerns, please contact our Supporter Experience Team via email at [email protected]

The trust and support of our supporters mean everything to us, and we thank you for your continued understanding while investigations continue.

Frequently asked questions

On Monday 3 August, Beacon CRM informed us it was investigating a data security incident involving temporary unauthorised access to its IT systems. 

We are working closely with Beacon CRM and independent specialists to understand exactly what this means, and how the RNLI might be affected. However, Beacon CRM has advised all its customers to assume, as a precaution, that data stored within its systems may have been affected while investigations continue.

No, the RNLI has not experienced a cybersecurity incident affecting its IT systems. Beacon CRM, a third-party provider which holds some information relating to RNLI, recently informed us of a security incident it recently experienced. 

There is no indication the RNLI was specifically targeted. We are one of hundreds of charities and organisations that Beacon CRM works with who are potentially impacted.


The information relating to RNLI supporters held within Beacon CRM’s systems may include:

  • Your name
  • Postal address
  • Email address
  • Telephone number

Some supporter records also contained limited banking information. Where this existed, it was restricted to sort codes and partially masked account numbers. Full bank account details or credit/debit card information were not stored within Beacon CRM's systems.

Beacon CRM has not confirmed whether any RNLI data has been accessed or taken, and investigations remain ongoing. 

As soon as we were informed of the incident, we took immediate action to protect supporter information. This includes:

  • Suspending all work with Beacon CRM while investigations continue
  • Activating our Cyber Incident Response Team
  • Notifying the Information Commissioner's Office (ICO) and the Irish Data Protection Commission (DPC)
  • We continue to work with independent cybersecurity specialists and regulators to understand any potential impact and ensure appropriate action is taken. 

While there is currently no evidence that supporter information has been misused, personal information can be used to make phishing and scam attempts appear more convincing. 

As a precaution, we recommend our supporters:

  • Remain vigilant for suspicious emails, text messages, phone calls or correspondence claiming to be from the RNLI or other trusted organisations.
  • Take care before clicking links or opening attachments in unexpected communications.
  • Never share passwords, one-time security codes or financial information in response to unsolicited requests.
  • Regularly monitor financial accounts and statements for unusual activity.
  • Report suspected fraud or scam activity to the appropriate authorities.