Update on Beacon CRM cybersecurity incident
We want to let volunteers know about a data security incident affecting Beacon CRM, a third-party supplier providing our proposed supporter database.
While this matter does not affect any RNLI IT systems directly, we understand that some volunteers and staff are also supporters of RNLI, and we’re truly sorry for any concern this may cause.
As investigations continue, we are committed to keeping all volunteers informed and know many of you may have questions about the incident and its potential impact on the RNLI, our supporters and the CRM programme.
If you have any questions or require further support, please do not hesitate to reach out to your manager, or email [email protected]
What happened?
On Monday 3 August, Beacon CRM informed the RNLI that it was investigating a data security incident affecting its systems.
Although the RNLI had not yet started using Beacon CRM to manage supporter information, some supporter and organisational data had been stored within Beacon CRM's systems as part of the development of our proposed new supporter database.
At this stage, Beacon CRM has not confirmed whether any RNLI data has been accessed and has advised all its customers to assume, as a precaution, that data stored within its systems may have been affected while investigations continue.
There is no indication the RNLI was specifically targeted. We are one of hundreds of charities and organisations potentially affected by this incident.
What information may be involved?
The information held within Beacon CRM's systems may include the names, postal addresses, email addresses and telephone numbers of RNLI supporters and organisational contacts.
Some supporter records also contained limited banking information. Where this existed, it was restricted to sort codes and partially masked account numbers.
Full bank account details or credit/debit card information were not stored within Beacon CRM's systems.
Additionally, no HR or employment data relating to RNLI colleagues or volunteers was held in Beacon CRM.
Importantly, Beacon CRM has not confirmed whether any RNLI data has been accessed, and investigations remain ongoing.
What action has the RNLI taken?
Protecting the personal information entrusted to us is extremely important, and we acted immediately on being informed of the incident.
Our response, coordinated through the Cyber Incident Response Team, includes:
- Suspending all work involving Beacon CRM while investigations continue
- Notifying the Information Commissioner's Office (ICO) and the Irish Data Protection Commission (DPC)
- Working with independent cybersecurity specialists, regulators and legal advisers to understand any potential impact and ensure appropriate action is taken.
Our immediate priority is to establish whether any RNLI supporter data has been compromised and to fully understand the impact of the incident.
What does this mean for supporters?
At present, we are not aware of any misuse of RNLI supporter information arising from this incident.
However, as a precaution, we will be advising supporters to remain vigilant for suspicious emails, text messages, phone calls or correspondence claiming to be from the RNLI or other trusted organisations.
If our investigation identifies that any supporters have been affected, we will contact them directly as soon as possible, explain what this means and provide any guidance and support they need.
What should volunteers do?
At present, no action is required from most volunteers and staff.
However:
- Please remain vigilant for suspicious emails, messages or phone calls claiming to be from the RNLI, Beacon CRM or other organisations.
- We ask you avoid speculating about the incident internally or externally based on incomplete information.
- If supporters, other volunteers or partners raise concerns, please reassure them that investigations are ongoing and refer them to the latest official RNLI communications on our website here.
- Please direct any media enquiries to the Press Office at [email protected]
- If you receive anything suspicious or have concerns about information security, please follow normal reporting procedures and contact the appropriate team.
What happens next?
We are continuing to work closely with Beacon CRM, independent cybersecurity specialists and regulators to establish the facts as quickly as possible.
We are committed to being open and transparent as the situation develops and will provide further updates when more information becomes available.
We recognise this incident may be concerning and may also have implications for volunteers, staff and stakeholders connected to the CRM programme.
Over the coming days, we will be communicating directly with relevant groups about any specific impacts on planned activity, project timelines and next steps.
Thank you for your continued professionalism, patience and support while we work through this situation.