UK MoD Afghan Applicant Data Breach
Coverage from Committees - UK Parliament, Tech Times, and others

A February 2022 Ministry of Defence breach exposed personal details of Afghan relocation applicants, with the incident reportedly involving between roughly 18,500 and 33,000 people depending on whether family records are included.
Parliamentary scrutiny found weak procedures, inappropriate use of spreadsheets, inadequate training, delayed detection, and limited accountability, while a superinjunction restricted disclosure for almost two years. The breach led to security risks, secret relocation measures, and renewed examination of flawed Afghan resettlement decisions.
The story adds a more specific account of how long the breach went undetected and clarifies that the exposed population may be larger when family members are counted. It also strengthens the secrecy and accountability angle by emphasizing the superinjunction and the parliamentary findings on weak controls and training.
The story is now framed less around a one-off disclosure and more as a broader systemic governance failure, with Parliament emphasizing weak controls, poor accountability, and unresolved remediation. The updated version also adds the ICO and sharper criticism of the tools and access practices involved.
- Email exposed Excel and SharePoint records, not only a spreadsheet.
- The Ministry of Defence failed to detect the disclosure for about 18 months.
- The Information Commissioner's Office is now part of the story.
- Parliament called the incident a foreseeable systemic failure.
- Recommendations now call for named senior responsibility for data protection failures.
The story is now framed less as a single breach and more as an accountability and governance case, with stronger emphasis on parliamentary scrutiny, legal secrecy, and disputed harm claims. The current version also broadens the official response to include overturned Afghan special forces decisions and trust in government handling.
The main update is that the story now includes a quantified resettlement obligation: the MoD estimates up to 27,278 people may qualify because of the breach. The current version also sharpens the accountability angle by adding legal claims, public-cost scrutiny, and a named military witness before Parliament.
- MoD estimates up to 27,278 people may qualify for resettlement.
- Legal claims have emerged from the breach.
- Defence Committee scrutiny now includes public costs.
- First Sea Lord General Sir Gwyn Jenkins is now a named figure.
- Separate reviews overturned 884 Afghan Special Forces decisions.
The story has become more concrete and severe: the breach’s scale, discovery timeline, and reported human harms are now specified, alongside secret relocation measures. It also expands beyond the original inquiry into Afghan Special Forces application reviews, adding a second related decision-making problem.
- Roughly 19,000 applicants were exposed; dataset reportedly held 33,000 rows.
- Leak was discovered after parts appeared online in August 2023.
- Research reported 49 deaths and 87% of surveyed Afghans faced threats.
- Many affected people were secretly relocated to the UK.
- Afghan Special Forces reviews include 884 overturned decisions.
The UK Defence Committee has opened a wide-ranging inquiry into a Ministry of Defence data breach that exposed personal details of thousands of Afghan resettlement applicants and their families. The inquiry is examining how the breach happened, why secrecy was maintained through a superinjunction, and whether government decisions on resettlement and risk management were timely and appropriate. It also widens into the performance and consequences of Afghan resettlement schemes more broadly, including costs, public trust, and the handling of affected people.
