Skip to content
Back to Blog
medium severity September 11, 2026 · 4 min read Unverified claim — what this is

RNLI volunteers' details reportedly shared online after Portsmouth protests

If you are a customer of RNLI volunteers', here’s what is being claimed, and what it would mean for you.

News outlets report that some RNLI volunteers were identified and abused online after protests in Portsmouth on 6 September 2026. The RNLI has confirmed abuse and family threats against some volunteers and staff, but it has not confirmed that full names, photographs or home addresses were published. If you were not one of those people, this is not a leak of your information.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
RNLI volunteers' details reportedly shared online after Portsmouth protests

According to multiple news outlets, protests took place in Portsmouth on Sunday 6 September 2026 after the RNLI helped bring people ashore from a Channel dinghy (reports put the number at around 120 to 140). RNLI crews were also reported to have been there for protester safety. In the days that followed, newspapers and broadcasters said some volunteers were identified on social media.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The RNLI itself has not confirmed that photographs, full names or home addresses were published. On 8 September 2026 the charity did say that some volunteers and staff had faced online abuse, and in the worst cases physical abuse, with threats to them and their families. It called that “wholly unacceptable.” Sussex Police, according to the same reporting, said they were aware of offensive and threatening posts, were supporting the RNLI on safety, and were investigating whether any of the content was criminal. Claims that two volunteers had photos, names and home addresses circulated come from news reports and social-media analysis, not from the RNLI’s own statement.

This is not a leak of the RNLI’s files

Headlines about volunteers being “doxxed” sound like a company lost a list — donors, staff, anyone who ever gave a phone number. That is not what has been reported. Nobody has described a hack of RNLI systems, a stolen membership file, or a regulator filing. This was described as other people targeting volunteers after a public incident, then arguing about it online.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

That distinction changes what the story means for you. Coverage has mostly followed the politics: Channel crossings, insults such as “traitor,” and who was in the right at Portsmouth. The practical fact is narrower. According to BBC Verify, a volunteer said his picture was shared, that he had been wrongly identified as part of the migrant rescue, and that the abuse included talk of tracking families. The Independent and others reported that photos, full names and home addresses of two volunteers were circulated after 6 September. A government minister, Lisa Nandy, referred in Parliament to names, addresses and photographs being “reportedly shared.” The RNLI’s own words stayed more general: online abuse, some physical abuse, threats to families, and “deliberate misinformation” about its role.

The honest read is this. For almost everyone seeing those headlines, including people who donate to the RNLI or live near a station, this incident does not put your details in those posts. For a small number of volunteers and staff — the charity said “some”; many articles said two — hostile strangers tried to make them identifiable, and some of those identifications were reported as wrong. If home addresses really were attached, that is serious for those households. It is still not a signal that the RNLI lost a database of the public. We cannot check whether you were one of the people named. That kind of targeting does not sit in a list anyone can scan.

What to actually expect

  • You should not expect an RNLI message saying your personal data was allegedly stolen. Nothing in the charity’s statement, or in the police comments reported alongside it, describes a theft of the organisation’s files.
  • Posts already online may keep being copied. BBC Verify reported that some were viewed millions of times. That kind of spread does not quietly expire in a few days.
  • Sussex Police said investigations were ongoing. There has been no public confirmation of whose details were accurate, whether any home address in a post was correct, or what exactly happened in the physical-abuse cases the RNLI mentioned.
  • If you volunteer or work for the RNLI, the near-term change that was reported is internal: the charity said it would protect its people and later reviewed security, including advice on branded clothing. That is not a public tool for everyone else to “check if you were affected.”

What you can and cannot fix

If a name, a photograph or a home address was put on social media and widely seen, it cannot be pulled back. Copies and screenshots remain. No one can honestly promise to remove that material from the internet.

  • If you have no reason to think you were named or pictured in those posts, there is nothing from this incident you need to repair. Being a supporter, a donor, or a neighbour of a station does not put you in the posts that were described.
  • If you believe you were identified, the useful path in the reporting is safety support from the RNLI and the police, not a hope that every copy will be deleted. Police also warned against behaviour that could hinder rescue work.
  • The lever that actually moves, if you were named, is the rest of your public footprint. A viral post with a face and a name becomes much easier to act on when people-search listings add relatives, phone numbers, employers and previous addresses. Those extra listings, unlike the original posts, can often be removed or suppressed. That is worth doing because it is what turns a hostile identifications into a knock at the door — and it is one of the few parts of this you can still change.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
RNLI volunteers' is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed September 11, 2026
Last reviewed September 11, 2026
Affected Unconfirmed
Data exposed Full namesPhotographsHome addresses
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email