Full Report
Met ordered to improve safeguards after two preventable data breaches
Analysis Summary
# Incident Report: Metropolitan Police Service (MPS) Data Breaches
## Executive Summary
The UK’s Information Commissioner’s Office (ICO) has issued an enforcement notice and reprimand against the Metropolitan Police Service (MPS) following two preventable data breaches in 2024. These incidents involved the disclosure of a stalking victim's new address to her stalker and the exposure of "honeytrap" victims' identities via an email CC error. The breaches highlighted systemic failures in data protection training and information assurance within the force.
## Incident Details
- **Discovery Date:** January 2024 (Stalking case); Mid-2024 (Honeytrap case)
- **Incident Date:** January 2024 & May 2024
- **Affected Organization:** Metropolitan Police Service (MPS)
- **Sector:** Law Enforcement / Public Sector
- **Geography:** London, United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** January 2024
- **Vector:** Human Error / Procedural Failure
- **Details:** Officers failed to redact sensitive witness statements before handing them to a defendant subject to an interim Stalking Protection Order (SPO).
### Lateral Movement
- **N/A:** These were not network-based intrusions but internal procedural failures leading to unauthorized disclosure.
### Data Exfiltration/Impact
- **Stalking Incident:** A victim’s new phone number and home address, as well as contact details for her friends and family, were handed directly to the stalker.
- **Honeytrap Incident:** The email addresses of 18 individuals connected to the UK Parliament were exposed to each other due to the failure to use the BCC (Blind Carbon Copy) function.
### Detection & Response
- **Detection:** The victim reported receiving a call from the stalker on her new number; the MPS self-reported the BCC error on the day it occurred.
- **Response:** The stalker was eventually arrested and imprisoned; the ICO launched an investigation leading to a formal enforcement notice.
## Attack Methodology
- **Initial Access:** Misconfiguration of physical documents (lack of redaction) and digital communications (BCC failure).
- **Persistence:** N/A (Insider negligence).
- **Privilege Escalation:** N/A.
- **Defense Evasion:** Failure to follow internal "redaction warnings" provided during the SPO application process.
- **Credential Access:** N/A.
- **Discovery:** N/A.
- **Lateral Movement:** N/A.
- **Collection:** Aggregation of witness statements and victim contact lists.
- **Exfiltration:** Manual handover of unredacted documents to a defendant; improper use of email distribution lists.
- **Impact:** Physical safety risk to a victim; exposure of identities in a sensitive political investigation.
## Impact Assessment
- **Financial:** Potential for future fines; administrative costs of ICO compliance monitoring.
- **Data Breach:** PII (Personally Identifiable Information) including home addresses, phone numbers, and email addresses.
- **Operational:** Diversion of resources to meet ICO enforcement requirements (12-month compliance window).
- **Reputational:** Severe damage to public trust, particularly regarding the protection of vulnerable victims and high-profile political figures.
## Indicators of Compromise
- **Network indicators:** N/A
- **File indicators:** Unredacted PDF/physical witness statements.
- **Behavioral indicators:** Failure of staff to complete mandatory data protection training (some officers were over four years out of date).
## Response Actions
- **Containment:** Reporting the BCC breach to the ICO within 24 hours.
- **Eradication:** Arrest and imprisonment of the stalker following his re-entry into the UK.
- **Recovery:** Implementation of a mandatory 12-month improvement plan for data protection training.
## Lessons Learned
- **Key Takeaways:** Policies and reminders are ineffective if they are not audited, enforced, and supported by up-to-date training.
- **What could have been done better:** Redaction processes should have been verified by a secondary officer before document release. Automated systems for bulk emailing should be used instead of manual BCC in high-stakes investigations.
## Recommendations
- **Training:** Achieve 100% completion rate for data protection training across all force tiers.
- **Technical Controls:** Implement software-based "BCC warnings" or use dedicated outbound communication platforms for sensitive updates.
- **Audit:** Conduct quarterly reviews of email communication methods and redaction workflows for sensitive legal documents.