
Ministry of Defence Afghan Data Breach Caused by Foreseeable Failures
The Ministry of Defence's (MoD) catastrophic data breach, which exposed the identities of hundreds of Afghan individuals eligible for relocation to the UK, was a consequence of “foreseeable failures” exacerbated by the department’s excessive reliance on secrecy, a new parliamentary report asserts.
The Commons' Defence Committee found that the MoD deliberately avoided consulting outside specialists, choosing instead to use national security classification as a “shield” against proper scrutiny and external expertise. This institutional aversion to external input directly contributed to the security lapse.
In September 2021, the MoD inadvertently disclosed personal details, including names, photographs, and even some medical information, of Afghan nationals seeking relocation under the Afghan Relocations and Assistance Policy (ARAP). These individuals had assisted British forces in Afghanistan and were subsequently placed at severe risk following the Taliban's return to power.
The report details that some individuals affected by the breach were forced to flee their homes, while others were compelled to change their phone numbers due to the exposure. Despite the grave implications, the MoD’s internal review into the incident was deemed “not good enough” by the Committee, failing to adequately address the systemic issues that allowed the breach to occur.
The Committee’s findings underscore a pattern of negligence within the MoD, where procedural safeguards were either absent or ignored, and the perceived need for operational secrecy overshadowed the imperative for robust data protection measures. This approach ultimately endangered those the UK had a moral obligation to protect.






