Beacon CRM cybersecurity incident: Latest update
We want to keep volunteers and colleagues updated on the ongoing cybersecurity incident affecting Beacon CRM, a third-party supplier involved in the development of our proposed new supporter database.
While this incident does not affect any RNLI IT systems, we recognise that some volunteers and colleagues are also RNLI supporters, and we'd like to reiterate our heartfelt apologies for any concern this may have caused.
What's the latest?
On Monday 3 August, Beacon CRM informed us it was investigating unauthorised access to its systems.
Beacon CRM has now advised affected organisations, including the RNLI, to assume that data stored within its systems has been accessed and taken.
While it cannot confirm exactly which records were accessed or downloaded, analysis of the incident indicates that a significant volume of data was likely downloaded by the unauthorised third party.
Importantly, there is currently no evidence that information relating to RNLI supporters has been published, shared online or otherwise misused.
There is no indication that the RNLI was specifically targeted, and this incident relates to Beacon CRM's systems, not RNLI's own IT infrastructure.
We will continue to work closely with Beacon CRM, independent cyber security specialists and relevant authorities to monitor the situation as investigations continue.
What information may be involved?
The information relating to RNLI supporters held within Beacon CRM’s systems may include some or all of the following:
- Names
- Postal addresses
- Email addresses
- Telephone numbers
- Records of supporter interactions with the RNLI
- Incomplete bank account details (which could not be viewed in their entirety)
- Personal information shared with the RNLI when contacting us about services and activities - this may include more sensitive personal data such as health information.
The exact information varies between supporters because it is dependent on the relationship we have with you.
What action has the RNLI taken?
As soon as we were informed about the incident, we took immediate action.
This includes:
- Working with Beacon CRM, independent cyber security specialists and relevant authorities to understand the potential impact.
- Reviewing the information affected and assessing risks to individuals.
- Reporting the incident to relevant Data Protection regulators.
- Suspending any further data transfers with Beacon CRM.
- Continuing to monitor the situation and support affected individuals.
- Publishing information about the incident on our website.
Will the RNLI be writing to all supporters to inform them of this incident?
Protecting our supporters is our priority. Our investigation has shown that different groups of supporters may have been affected in different ways, so we are tailoring our approach accordingly.
Where we believe a supporter’s information may be at greater risk because of this incident, we are contacting them directly by letter and email to explain what has happened, what information may be involved, and any steps they may wish to take to help protect themselves.
We remain committed to being open and transparent with all our supporters and will continue to provide updates through our website, as well as RNLI Life, Lifeboat, Offshore and Your RNLI.
For supporters whose information is not believed to be significantly affected, we do not think it would be appropriate to contact them individually and risk causing unnecessary concern or alarm.
We will continue to keep our communications under review and provide further updates where appropriate.
Is there a police investigation?
Beacon CRM has confirmed it is cooperating with a criminal investigation being led by the Metropolitan Police into the unauthorised access to its systems.
This investigation relates to Beacon CRM and is not an investigation into the RNLI.
What should volunteers and staff do?
- Remain vigilant for suspicious emails, messages or phone calls.
- Avoid speculating internally or externally about the incident.
- Direct supporters with questions to [email protected].
- Direct media enquiries to [email protected].
- Report any suspicious activity through normal information security reporting channels.
What happens next?
We continue to work closely with Beacon CRM, cybersecurity specialists and regulators and to understand the full impact of the incident.
We are committed to being open and transparent and will provide further updates as more information becomes available.
Thank you for your continued support, understanding and professionalism.