Supporters of the Royal National Lifeboat Institution (RNLI) have been informed that their personal data may have been compromised in a recent cyberattack targeting a company the charity uses for customer relationship management. The RNLI issued a warning in a letter accompanying its autumn Lifeboat magazine, indicating that members’ names, contact information, and records of interactions with the organisation could have been accessed.

The breach involved Beacon CRM, a service provider whose systems were affected in late July during a broader cyberattack impacting approximately 1,500 charities. According to the RNLI, Beacon advised affected organisations to assume that data held within their systems had been stolen. Although there is currently no evidence that the personal data of RNLI supporters has been misused, shared, or made public, the charity is continuing to monitor the situation closely.

This warning comes amid heightened tensions surrounding the RNLI, which has recently faced coordinated protests from far-right activists opposing its efforts to rescue people attempting to reach the United Kingdom by small boats. Earlier this month, the Portsmouth lifeboat station was forced to temporarily close following clashes between border protesters and police near a landing point where the RNLI had assisted a dinghy carrying 120 asylum seekers. The confrontations resulted in injuries to police officers.

In the aftermath of the protests, RNLI volunteers reported being subjected to abuse both online and in person. The charity’s Portsmouth lifeboat station removed its Facebook page, while volunteers across the UK were advised to consider not wearing RNLI-branded clothing if they felt their safety could be at risk. Additionally, protests were held outside the RNLI’s headquarters in Poole, prompting the temporary closure of the organisation’s museum there.

Sir Robin Knox-Johnston, the RNLI vice-president, condemned the intimidation directed at staff and volunteers as “frankly quite disgraceful.” Despite calls from far-right groups urging people to halt donations, the RNLI has noted a significant increase in fundraising since the protests.

The RNLI emphasised that only a small portion of its rescue operations—approximately 1.2% last year, or 109 callouts out of 9,058—were related to small boats in the English Channel.

A report released by Beacon CRM following the cyberattack stated that there was no indication the incident targeted the company or any specific customer intentionally. The attacker reportedly contacted Beacon to declare the intent to delete any exfiltrated data and assured that no copies would be retained, sold, or shared.

An RNLI spokesperson reiterated that while the full extent of the data accessed cannot be confirmed, the organisation has been advised to assume the information was compromised. At present, there is no proof that supporter data has been publicly disclosed or otherwise exploited.