By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: MoD cyber breach put thousands of Afghan lives at risk | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > MoD cyber breach put thousands of Afghan lives at risk | Computer Weekly
News

MoD cyber breach put thousands of Afghan lives at risk | Computer Weekly

News Room
Last updated: 2025/07/15 at 10:18 PM
News Room Published 15 July 2025
Share
SHARE

A serious data breach at the UK’s Ministry of Defence, revealed for the first time today after the lifting of a superinjunction preventing the media from discussing the case, put at risk the personal data, and lives of thousands of Afghan citizens seeking relocation to the UK to protect them from Taliban reprisals after the group regained control of the country in 2021, two decades after they were ousted following the 9/11 terrorist attacks.

The cyber incident arose in early 2022 when a dataset containing details of over 18,000 people applying for asylum under the Afghan Relocations and Assistance Policy (Arap) and the Afghanistan Locally Employed Staff Ex-Gratia Scheme (EGS) on the basis they had worked with or for the UK during the Western occupation of the country, was released in error.

It has now emerged that about 18 months later, the MoD discovered that part of this dataset relating to nine individuals had been published on social media platform Facebook.

Fearing the consequences if this data was to fall into the hands of the Taliban, a superinjunction was granted in September 2023 against multiple outlets including The Daily Mail, The Daily Telegraph, The Financial Times, The Independent, the Press Association and The Times, stopping them from reporting details of the incident.

The lifting of the superinjunction comes following a review report prepared by former civil servant Paul Rimmer. This report concluded that should the dataset fall into the hands of the Taliban it would be “unlikely to substantially change an individual’s existing exposure” based on the volume of data already in the public domain.

Rimmer’s report also deemed it “unlikely” that the fact of an individual’s inclusion in the dataset would be grounds for the targeting of said individuals’ or their associates or families by the Taliban.

Besides the superinjunction, the incident also led to the establishment of a secret Afghan resettlement route – dubbed the Afghanistan Response Route (ARR), to fast-track the resettlement of a total of about 200 principal applicants, later broadened to 3,000.

This route is, as of today, closed, having relocated about 900 principal applicants and 3,600 family members at a cost of £400m, although the government confirmed that ARR offers made to about 600 more principals and their families who remain in Afghanistan will be honoured if taken up. It is likely that the final cost of the ARR will double.

In an oral statement to the House of Commons, defence secretary Ben Healey said: “It [the database] contained names and contact details of applicants – and some instances, information relating to the applicants’ family members. In a small number of cases … the names of members of Parliament, senior military officers and government officials were noted as supporting the application. 

“This was a serious departmental error. It was in clear breach of strict data protection protocols. And it was one of many data losses relating to the ARAP scheme during this period,” said the minister.  

Healey told the Commons that swift action was taken to remove the exposed data from Facebook, an internal investigation was mounted, and reports were made to the Information Commissioner’s Office (ICO) and the Metropolitan Police, which determined no criminal investigation was necessary.

“This serious data incident should never have happened,” said Healey. “It may have occurred three years ago under the previous government, but to all those whose information was compromised, I offer a sincere apology today on behalf of the British government.” 

The government has established a dedicated microsite related to the incident, where those who may have been exposed can check if they were affected, and access guidance on preserving their own personal cyber security.

“Human error remains a major cyber risk which, as has been highlighted by a single misjudged email that exposed thousands of personal details,” said ESET global cyber security advisor Jake Moore.

“While people aren’t always behind data breaches, they are often the cause of data loss or cyber attacks, which only reinforces the need for stronger technical safeguards and user training.

“The addition of enhanced secrecy inside the organisation may have also exacerbated the problem, but the lack of proper protocols ultimately reveals a fundamental weakness in the system’s defences,” said Moore. “Even a basic human mistake can undermine even the most sensitive national security operations.”

History of exposures

The latest breach to be disclosed is not the first that has affected the ARAP programme, although it is the most serious by a significant margin.

In September 2021, the MoD was forced to reveal that approximately 305 individuals had had their data exposed in two separate incidents.

In the first breach, an internal error at the MoD saw the email addresses and names of 250 Afghan interpreters awaiting relocation copied into the body of an email. Many of the recipients – mostly interpreters who had worked with British forces during the occupation of their homeland – compounded the error by hitting the ‘reply all’ function, potentially exposing details of their locations and cases.

In the second incident, which was disclosed just two days later, saw the email addresses and names of 55 individuals, exposed in a similar blunder.

In December 2023, the Information Commissioner’s Office (ICO) took the step of fining the MoD £350,000 – out of step with its usual policy of not fining public sector or government bodies – given the risk to life that the incident posed.

The ICO’s investigation found that Arap was operating contrary to ICO guidance which states organisations must put technical measures in place to avoid accidental bulk email disclosure.

It had failed to implement any such measures and was relying instead on staff members remembering to use the Blind Carbon Copy (BCC) function, which is not an adequate protective measure.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Secure Your Surroundings With Savings: The EufyCam S330 Kit Is Still 23% Off
Next Article Best Internet Providers in Bakersfield, California
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

ESWIN Computing EBC77 RISC-V SBC To Support Ubuntu Linux
Computing
Mansion House 2025: UK tech embraces chancellor’s reforms – UKTN
News
The deluge of faster Qi2.2 wireless chargers is here
News
Samsung Galaxy Z Fold 7 vs Oppo Find N5: Which ultra-thin foldable wins?
Gadget

You Might also Like

News

Mansion House 2025: UK tech embraces chancellor’s reforms – UKTN

1 Min Read
News

The deluge of faster Qi2.2 wireless chargers is here

3 Min Read
News

Faster wireless chargers coming to iPhone, but don’t buy one yet – 9to5Mac

3 Min Read
News

Windows 11 Will Soon Let You Show Copilot Your Whole Desktop

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?