Home Technology Catastrophic MoD data breach would not have happened if...
Technology

Catastrophic MoD data breach would not have happened if staff had been trained on Excel

Catastrophic MoD data breach would not have happened if staff had been trained on Excel
Key Points

Catastrophic MoD data breach would not have happened if staff had been trained on Excel Blunder which exposed personal details of tens of thousands of Afghans was ‘forseeable failure’ covered up by secrecy for ‘too long’, MPs said - Bookmark - CommentsGo to comments A catastrophic Ministry of Defence data breach that exposed the personal details of tens of thousands of Afghans was a “foreseeable failure” covered up by secrecy for “too long”, a damning investigation has concluded. In a report...

Catastrophic MoD data breach would not have happened if staff had been trained on Excel Blunder which exposed personal details of tens of thousands of Afghans was ‘forseeable failure’ covered up by secrecy for ‘too long’, MPs said - Bookmark - CommentsGo to comments A catastrophic Ministry of Defence data breach that exposed the personal details of tens of thousands of Afghans was a “foreseeable failure” covered up by secrecy for “too long”, a damning investigation has concluded. In a report from the influential defence select committee, MPs criticised the government for almost every aspect of their handling of the data breach, the resulting superinjunction – a court order so strict that even mentioning its existence was forbidden – and the covert evacuation of thousands of Afghan families. They concluded that “secrecy was maintained for too long, accountability was too weak, delivery was too fragmented, and affected Afghans were too often left without the information and support they needed”. The leak, in February 2022, exposed the details of 18,700 Afghans who said they were in danger from the Taliban because of their links to UK forces and now wanted to escape to Britain. The blunder triggered an unprecedented superinjunction used against the national media, including The Independent, and prompted a secret evacuation programme – the cost of which is still unclear but which likely ran into the billions of pounds. Following the revelation by this outlet and others in July last year of the hidden operation, MPs set up an inquiry to scrutinise what had happened. In their report, the defence selection committee concluded that: - The data breach could have been prevented if Ministry of Defence (MoD) personnel had received basic Excel training - By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place - The government did not strike “the right balance between operational secrecy and democratic accountability” – and the superinjunction was in place for too long - Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation programme - Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety. MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defence committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticising the lack of accountability within the civil service. The leak happened when an member of MoD personnel sent an Excel file outside of government. They thought the data sheet had the details of around 150 Afghan applicants in it, when it in fact had a hidden tab with details of over 18,500 others. The breach "could still have been prevented" if MoD personnel had "received basic training" on this, the report concluded. As of 9 June 2026, there were around 7,000 eligible people remained to relocate to the UK, of whom 3,700 are believed to be in Afghanistan. In April, the MoD told Afghan families approved for sanctuary in Britain that they will have to flee the Taliban-run country on their own. This has created a “two-tier system” where those who are able to raise the necessary funds can relocate but vulnerable and destitute families cannot. MPs said: “The government has not adequately explained how it will protect eligible Afghans who cannot safely, lawfully or affordably self-move to a third country for UK entry-clearance checks. This is a serious gap in the current model”. Chair of the defence committee Tan Dhesi MP said: “The latest ‘self-move’ policy risks excluding people the UK has promised to help, including some who should have been brought here years ago. “The broader picture is deeply troubling. The MoD should stick to defence – it should never have been left to run immigration casework schemes. Secrecy has been too easily used as a shield against proper accountability in areas far removed from sensitive operations”. Person A, an independent caseworker who alerted the government to the data breach in the summer of 2023, called on the government to “immediately reinstate third party support for approved families trying to escape from Afghanistan”. They added: “It is immoral to make our promise to resettle these families contingent on their ability to secure large loans at short notice. “We owe these men and women a debt of honour, and it’s time to move heaven and earth to keep the promises we made.” Professor Sara de Jong, from the Sulha Alliance, which supports Afghans who worked for the British army, welcomed the report’s call to help eligible Afghans who cannot evacuate themselves. Speaking about the impact of the data breach, she said: “These human costs, from physical risk to psychological damage, are much more significant than the government initially accepted, as I know from my daily contact with Afghans.” She also backed MPs’ conclusion that the independent ‘Rimmer’ review of Afghan data breach should not be “the final word” on whether someone has been put at risk. She concluded: “The report’s conclusions that the government kept the data breach secret for too long, avoiding public scrutiny and accountability to affected Afghans, and that ‘the government’s assumptions about who could be trusted were too pessimistic’, is a vindication for all those, who like me, were long aware of the data breach, but showed discretion in the interests of affected Afghans”. A MoD spokesperson said: “This incident should never have happened, and we acknowledge the significant impact it has had on many people. “Thousands of eligible Afghans have already been safely relocated to the UK, where they can rebuild their lives and we are committed to ensuring that we conclude the Afghan Resettlement Programme by the end of this parliament. “We are learning the lessons from this incident and important reforms are already in place, including improved data protection standards, strengthened case-working processes and better programme governance.” Join our commenting forum Join thought-provoking conversations, follow other Independent readers and see their replies Comments
Afghans (ORG) Ministry of Defence (ORG) MPs (ORG) Afghan (ORG) Taliban (ORG) UK (LOCATION) Britain (LOCATION) Independent (ORG) Ministry of Defence (MoD (ORG) Afghanistan (LOCATION) MoD (ORG)
Originally published by The Independent UK Read original →