The recent Met Police data breach has put the contact details of alleged Al Fayed victims at risk. The incident, involving the incorrect use of email addressing, highlights the ongoing threat posed by human error in managing sensitive personal information.
Met Police Data Breach: What Happened?
On 7 June 2024, the Metropolitan Police Service (Met Police) admitted to a data breach affecting individuals who had signed up for monthly updates related to the Al Fayed case. Instead of using the blind carbon copy (BCC) function to conceal recipients’ email addresses, an officer used the standard carbon copy (CC) field. As a result, every recipient could see the email addresses of all others on the distribution list.
This error exposed the personal contact details of multiple individuals who were receiving sensitive updates. The information included email addresses and potentially names, depending on the format of the recipients’ email accounts. The breach directly affected those who had previously requested confidential updates from the Met Police regarding cases linked to the Al Fayed family.
- Date of incident: 7 June 2024
- Organisation: Metropolitan Police Service
- Affected individuals: Recipients of the Al Fayed victims’ update mailing list
- Type of data exposed: Email addresses and possibly associated names
The Met Police promptly issued an apology to those affected and self-reported the incident to the Information Commissioner’s Office (ICO). An internal review was launched to assess the extent of the breach and to identify the precise number of recipients involved.
How the Breach Occurred and Which Controls Failed
This data breach was not the result of a cyberattack or deliberate insider threat. Instead, it was a classic example of accidental data exposure due to human error. When sending bulk communications to a list of victims and other interested parties, the officer responsible mistakenly used the CC field. This meant that every recipient of the email could view the full list of others who had received the communication.
Such errors often occur in organisations that rely on manual processes for email distribution, especially when dealing with sensitive or confidential groups. In this case, the following controls failed or were absent:
- Manual Emailing: No use of a secure mailing platform to automate recipient privacy
- Policy Enforcement: No enforced requirement for BCC on sensitive group messages
- Data Loss Prevention (DLP): Absence of automated DLP checks to detect and warn against bulk CC exposures
- Training: Inadequate staff training or awareness on the risks of improper email field use
The breach serves as a reminder that, despite increasing awareness of technical cyber threats, simple process failures remain a significant risk to data protection. The ICO and privacy advocates have repeatedly warned that human error accounts for a large proportion of reportable data breaches in the UK public sector.
Timeline and Response to the Incident
The timeline of events provides insight into how quickly the breach was identified and addressed:
- 7 June 2024: The update email was sent from the Met Police to the Al Fayed victims’ mailing list using the CC field.
- Shortly after sending, the error was identified internally, likely either by a recipient reporting the issue or through internal monitoring.
- The Met Police issued an immediate apology to those affected, acknowledging the exposure of contact details.
- The incident was self-reported to the Information Commissioner’s Office, as required by UK data protection law.
- An internal review was launched to determine the root cause and prevent recurrence.
While the Met Police acted swiftly in response and followed regulatory protocol, the breach itself could have undermined the privacy and confidence of those involved. The fact that the victims’ details were linked to a sensitive and high-profile case further increased the potential reputational impact.
Current Status and Ongoing Risks
At the time of writing, there is no evidence that malicious actors have exploited the exposed data. However, the nature of the breach means that all recipients of the email now possess the contact details of other victims or interested parties. This could expose individuals to unwanted contact, phishing attempts, or further privacy violations if the information is mishandled by any recipient.
The Information Commissioner’s Office is expected to review the incident and may issue recommendations or enforcement actions depending on the findings of the internal review. The Met Police has not disclosed the exact number of individuals affected but has reaffirmed its commitment to improving procedures and staff training to prevent such incidents in the future.
Why This Data Breach Matters
This breach is significant because it demonstrates how a simple oversight in routine communication can expose sensitive personal data, even within highly regulated organisations. The use of bulk email communications without secure controls remains a persistent risk across many sectors, especially where victims or vulnerable individuals are involved.
The incident also highlights the legal and reputational risks faced by public sector bodies under UK data protection law, in particular the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
What Organisations Should Do Now
- Review internal policies on bulk email communications, ensuring BCC is enforced for sensitive groups.
- Adopt secure mailing platforms that automate privacy and reduce human error.
- Provide targeted staff training on email security and data protection responsibilities.
- Consider implementing DLP solutions to detect and alert on similar risks in real time.
Immediate action to strengthen controls and staff awareness is vital to prevent a repeat of such incidents.
Originally reported by bbc.co.uk.






