RNLI / Beacon CRM supporters data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
The Royal National Lifeboat Institution (RNLI) warned supporters in a letter accompanying the autumn issue of its Lifeboat magazine that personal information held by an external customer-relationship management provider may have been taken in a supplier cyber-attack.
The supplier is Beacon CRM, a UK platform used by charities to manage fundraising and supporter relationships. Per The Guardian (September 20, 2026) and the RNLI’s own statement quoted there, Beacon advised affected organizations — including the RNLI — to assume that data held within its systems was taken. Beacon could not confirm exactly which records were accessed or downloaded. The underlying Beacon incident affected on the order of ~1,500 charities and began in late July 2026 (public charity notices and Beacon updates followed in August; Beacon’s later incident reporting described July 27–28 activity and a likely compromised AWS access key in public JavaScript build artifacts).
This is not a confirmed breach of RNLI’s own IT systems. The RNLI said its own systems were not compromised. The newsworthy September development is the RNLI’s direct supporter warning about the earlier Beacon vendor incident.
The RNLI said that at this stage there is no evidence that information relating to RNLI supporters has been published, shared online, or otherwise misused. Beacon has separately said (in coverage of its incident report) that a threat actor indicated they would delete exfiltrated data and not retain, sell, or share copies — treat that as an unverified actor claim, not a guarantee.
The RNLI has not published an official count of how many of its supporters are in scope. Do not invent an RNLI-specific headcount from Beacon’s charity-customer totals.
Sources
- RNLI warns supporters their personal information may have been hacked – The Guardian (Sep 20, 2026)
- RNLI spokesperson statement as quoted in The Guardian (Beacon advised assume-taken; no evidence of publish/misuse of RNLI supporter data at time of statement)
- Background on Beacon CRM July 2026 incident / ~1,500 charities: SecurityWeek and other August 2026 Beacon customer coverage (vendor context — not a new RNLI system hack)
What data was exposed
Per the RNLI letter as reported by The Guardian and related coverage, potentially affected information may include (depending on how individual supporter records were held in Beacon):
- Name
- Contact details (postal / email / phone, as held)
- Records of interactions with the RNLI
- Donation / fundraising interaction history (cited in secondary charity-sector coverage of Beacon customer notices; treat as possible, not proven for every RNLI record)
Payment card numbers, bank account numbers, and sort codes are not described as part of RNLI’s Beacon CRM warning in the Guardian piece; other Beacon-customer charities have stated those payment fields were not stored in the CRM. Do not claim card or bank dump exposure for RNLI without a primary RNLI statement saying so.
Breach details
| Detail | Value |
|---|---|
| Breach name | RNLI supporters via Beacon CRM (vendor incident) |
| Date | Beacon malicious activity reported ~July 27–28, 2026; RNLI supporter letter with autumn Lifeboat magazine (reported Sep 20, 2026) |
| Disclosed | RNLI warning reported September 20, 2026 (underlying Beacon incident public from early August 2026) |
| Accounts affected | RNLI-specific N not disclosed; Beacon customer base ~1,500 charities (context only — not an RNLI headcount) |
| Domain | rnli.org / Beacon CRM (vendor) |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by the RNLI or Beacon CRM; it reflects a publicly reported security incident and subsequent supporter notification.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data that may have been exposed, here are the steps you should take:
- If you are an RNLI supporter or member, watch for official RNLI communications about this Beacon incident; prefer contacts from rnli.org over unsolicited messages.
- Be alert to phishing or harassment that uses your name, address, phone, or donation history and claims to be from the RNLI, Beacon, or “charity verification” teams.
- Volunteers and visible supporters: consider the RNLI’s broader safety guidance in the current environment (e.g. branded clothing / social profiles) separately from this CRM notice — doxxing risk is a social-threat context, not proof your record was published.
- Do not assume payment cards were stolen from this CRM path unless an official RNLI notice says so; still monitor bank/card statements if you donate by card through other channels.
- Treat actor claims that data “will be deleted” as unverified.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- What to do after a data breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.