RNLI volunteers' details reportedly shared online after Portsmouth protests
If you are a customer of RNLI volunteers', here’s what is being claimed, and what it would mean for you.
News outlets report that some RNLI volunteers were identified and abused online after protests in Portsmouth on 6 September 2026. The RNLI has confirmed abuse and family threats against some volunteers and staff, but it has not confirmed that full names, photographs or home addresses were published. If you were not one of those people, this is not a leak of your information.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
RNLI volunteers' customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
According to multiple news outlets, protests took place in Portsmouth on Sunday 6 September 2026 after the RNLI helped bring people ashore from a Channel dinghy (reports put the number at around 120 to 140). RNLI crews were also reported to have been there for protester safety. In the days that followed, newspapers and broadcasters said some volunteers were identified on social media.
The RNLI itself has not confirmed that photographs, full names or home addresses were published. On 8 September 2026 the charity did say that some volunteers and staff had faced online abuse, and in the worst cases physical abuse, with threats to them and their families. It called that “wholly unacceptable.” Sussex Police, according to the same reporting, said they were aware of offensive and threatening posts, were supporting the RNLI on safety, and were investigating whether any of the content was criminal. Claims that two volunteers had photos, names and home addresses circulated come from news reports and social-media analysis, not from the RNLI’s own statement.
This is not a leak of the RNLI’s files
Headlines about volunteers being “doxxed” sound like a company lost a list — donors, staff, anyone who ever gave a phone number. That is not what has been reported. Nobody has described a hack of RNLI systems, a stolen membership file, or a regulator filing. This was described as other people targeting volunteers after a public incident, then arguing about it online.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
That distinction changes what the story means for you. Coverage has mostly followed the politics: Channel crossings, insults such as “traitor,” and who was in the right at Portsmouth. The practical fact is narrower. According to BBC Verify, a volunteer said his picture was shared, that he had been wrongly identified as part of the migrant rescue, and that the abuse included talk of tracking families. The Independent and others reported that photos, full names and home addresses of two volunteers were circulated after 6 September. A government minister, Lisa Nandy, referred in Parliament to names, addresses and photographs being “reportedly shared.” The RNLI’s own words stayed more general: online abuse, some physical abuse, threats to families, and “deliberate misinformation” about its role.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
The honest read is this. For almost everyone seeing those headlines, including people who donate to the RNLI or live near a station, this incident does not put your details in those posts. For a small number of volunteers and staff — the charity said “some”; many articles said two — hostile strangers tried to make them identifiable, and some of those identifications were reported as wrong. If home addresses really were attached, that is serious for those households. It is still not a signal that the RNLI lost a database of the public. We cannot check whether you were one of the people named. That kind of targeting does not sit in a list anyone can scan.
What to actually expect
- You should not expect an RNLI message saying your personal data was allegedly stolen. Nothing in the charity’s statement, or in the police comments reported alongside it, describes a theft of the organisation’s files.
- Posts already online may keep being copied. BBC Verify reported that some were viewed millions of times. That kind of spread does not quietly expire in a few days.
- Sussex Police said investigations were ongoing. There has been no public confirmation of whose details were accurate, whether any home address in a post was correct, or what exactly happened in the physical-abuse cases the RNLI mentioned.
- If you volunteer or work for the RNLI, the near-term change that was reported is internal: the charity said it would protect its people and later reviewed security, including advice on branded clothing. That is not a public tool for everyone else to “check if you were affected.”
What you can and cannot fix
If a name, a photograph or a home address was put on social media and widely seen, it cannot be pulled back. Copies and screenshots remain. No one can honestly promise to remove that material from the internet.
- If you have no reason to think you were named or pictured in those posts, there is nothing from this incident you need to repair. Being a supporter, a donor, or a neighbour of a station does not put you in the posts that were described.
- If you believe you were identified, the useful path in the reporting is safety support from the RNLI and the police, not a hope that every copy will be deleted. Police also warned against behaviour that could hinder rescue work.
- The lever that actually moves, if you were named, is the rest of your public footprint. A viral post with a face and a name becomes much easier to act on when people-search listings add relatives, phone numbers, employers and previous addresses. Those extra listings, unlike the original posts, can often be removed or suppressed. That is worth doing because it is what turns a hostile identifications into a knock at the door — and it is one of the few parts of this you can still change.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Booking.com Customer Details Exposed — April 2026
A breach of Booking.com customer-detail records was disclosed in April 2026, with travel-history dat…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…