UK MoD Afghan Applicant Data Breach
Coverage from Committees - UK Parliament, Tech Times, and others

A February 2022 Ministry of Defence breach exposed personal details of Afghan relocation applicants, with the incident reportedly involving between roughly 18,500 and 33,000 people depending on whether family records are included.
Parliamentary scrutiny found weak procedures, inappropriate use of spreadsheets, inadequate training, delayed detection, and limited accountability, while a superinjunction restricted disclosure for almost two years. The breach led to security risks, secret relocation measures, and renewed examination of flawed Afghan resettlement decisions.
The story adds a more specific account of how long the breach went undetected and clarifies that the exposed population may be larger when family members are counted. It also strengthens the secrecy and accountability angle by emphasizing the superinjunction and the parliamentary findings on weak controls and training.
The story is now framed less around a one-off disclosure and more as a broader systemic governance failure, with Parliament emphasizing weak controls, poor accountability, and unresolved remediation. The updated version also adds the ICO and sharper criticism of the tools and access practices involved.
