Donate now

Beacon CRM cybersecurity incident: Latest update

We want to keep volunteers and colleagues updated on the ongoing cybersecurity incident affecting Beacon CRM, a third-party platform which the RNLI uses to process some RNLI supporter data. 

A row of yellow RNLI lifeboat kit hanging up

RNLI

While this incident does not affect any RNLI IT systems, we recognise that some volunteers and colleagues are also RNLI supporters, and we are committed to sharing updates and communicating transparently. 

What's the latest?

On Monday 3 August, Beacon CRM informed us it was investigating unauthorised access to its systems.

Beacon CRM has now advised affected organisations, including the RNLI, to assume that data stored within its systems has been accessed and potentially taken.

While it cannot confirm exactly which records were accessed or downloaded, analysis of the incident indicates that a significant volume of data was likely downloaded by the unauthorised third party.

Importantly, there is currently no evidence that information relating to RNLI supporters has been published, shared online or otherwise misused.

There is no indication that the RNLI was specifically targeted, and this incident relates to Beacon CRM's systems, not RNLI's own IT infrastructure.

We will continue to work closely with Beacon CRM, independent cyber security specialists and relevant authorities to monitor the situation as investigations continue.

What information may be involved?

The information relating to RNLI supporters held within Beacon CRM’s systems may include some or all of the following:

  • Names
  • Postal addresses
  • Email addresses
  • Telephone numbers
  • Records of supporter interactions with the RNLI
  • Incomplete bank account details (which could not be viewed in their entirety)
  • Personal information shared with the RNLI when contacting us about services and activities.

The exact information varies between supporters because it is dependent on the relationship we have with you.

What action has the RNLI taken?

As soon as we were informed about the incident, we took immediate action.

This includes:

  • Working with Beacon CRM, independent cyber security specialists and relevant authorities to understand the potential impact.
  • Reviewing the information affected and assessing risks to individuals.
  • Reporting the incident to relevant Data Protection regulators.
  • Suspending any further data transfers with Beacon CRM.
  • Continuing to monitor the situation and support affected individuals.
  • Publishing information about the incident on our website.

Will the RNLI be writing to all supporters to inform them of this incident?

Protecting our supporters is our priority. Our investigation has shown that different groups of supporters may have been affected in different ways, so we are tailoring our approach accordingly.

Where we believe a supporter’s information may be at greater risk because of this incident, we are contacting them directly by letter and email to explain what has happened, what information relating to them may have been involved, and any steps they may wish to take to help protect themselves.

We will continue to keep our communications under review and provide further updates where appropriate.

Is there a police investigation?

Beacon CRM has confirmed it is cooperating with a criminal investigation being led by the Metropolitan Police into the unauthorised access to its systems.

This investigation relates to Beacon CRM and is not an investigation into the RNLI.

What should volunteers and staff do?

  • Direct supporters with questions to [email protected].
  • Direct media enquiries to [email protected].
  • Report any suspicious activity through normal information security reporting channels.

Our volunteer and staff database has not been impacted and no action is required from volunteers and staff. For our volunteers and staff who are also supporters, we have provided more information in our FAQ’s

What happens next?

We continue to work closely with Beacon CRM, cybersecurity specialists and regulators and to understand the full impact of the incident. 

Thank you for your continued support, understanding and professionalism.