The United Kingdom’s Ministry of Defence has disclosed that nearly 50 incidents of data breaches and personal information leaks have occurred within its programs related to Afghan resettlement and local staff assistance.
According to a Thursday, October 23, report by Public Technology UK, David Williams, the Permanent Secretary of the Ministry of Defence, informed Parliament in a letter about the data breaches affecting the “Afghan Relocations and Assistance Policy (ARAP)” and the “Intimidation Scheme for Locally Employed Staff.”
Williams stated that only five of the incidents were formally reported to the Information Commissioner’s Office (ICO). At the same time, most cases involved emails or WhatsApp messages containing personal information that were sent in error.
Among the breaches, one incident occurred when MoD officials failed to use the BCC option in group emails, allowing hundreds of recipients to see the names and contact details of others on the list, an error that led to a £350,000 fine for the ministry in 2021.
Williams added that the largest breach occurred in February 2022, involving data on more than 18,000 Afghan applicants seeking resettlement in the UK.
The issue became public after a confidential court order was lifted in July this year.
He further noted that although only some of these incidents were reported to the ICO, the watchdog confirmed that the MoD’s reporting decisions were deemed “acceptable.”
The UK Parliament’s Defence Committee has also announced that it has launched a comprehensive investigation into the breaches and will hold hearings in the coming days.





