Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

LONDON METROPOLITAN POLICE SERVICE RECOGNIZES DATA BREACHES WITH HANDLING OF VICTIM'S PERSONAL INFORMATION



London's Metropolitan Police Service has been criticized by the UK's data protection regulator, the Information Commissioner's Office (ICO), over two preventable data breaches involving a victim. The breaches highlighted significant shortcomings in the MPS' handling of personal data and led to widespread criticism and calls for improvement.

  • The London Metropolitan Police Service (MPS) faced intense scrutiny over two data breaches involving sensitive personal information.
  • The breaches highlighted significant shortcomings in the MPS' handling of personal data, leading to widespread criticism and calls for improvement.
  • A preventable breach occurred when an officer sent CC-not-BCC emails exposing target's email addresses to each other.
  • Another breach involved a superintendent authorizing an application for a Stalking Protection Order (SPO) without redacting personal information.
  • The ICO issued an enforcement notice and reprimand to the MPS, emphasizing the need for effective training and monitoring of data protection policies.
  • The incidents highlight the importance of robust data protection practices within law enforcement agencies and the need for better training and awareness programs.



  • London's Metropolitan Police Service (MPS) recently faced intense scrutiny from the UK's data protection regulator, the Information Commissioner's Office (ICO), over two preventable data breaches involving sensitive personal information of a victim. The incidents, which occurred in 2024, highlighted significant shortcomings in the MPS' handling of personal data, leading to widespread criticism and calls for improvement.

    According to the ICO, the first breach involved an MPS superintendent authorizing an application for an interim Stalking Protection Order (SPO) in January 2024. As a result of this order, the victim had to change her phone number and home address. Despite being warned that all personal information should be redacted from the copy handed to the defendant, officers included unredacted witness statements and other documents, exposing the new address and phone number of the victim, as well as those of her friends and family members.

    It is reported that within days, after the man fled the UK, breaching his bail conditions, the victim reported to the MPS that the defendant had contacted her on her new phone number. A full SPO was subsequently issued in May 2024, and the stalker was arrested in July upon re-entering the UK. He was later charged with stalking offenses and imprisoned following a guilty plea.

    The second incident involved an MPS officer sending CC-not-BCC emails to 18 people connected to the UK Parliament who had been targeted in a honeytrap operation by "a malicious actor." The officer failed to use the BCC function, exposing the target's email addresses to one another. This breach occurred despite the fact that data protection training completion rates were low across the force.

    The ICO stated that regarding the honeytrap scheme, the officer who sent the email had not completed data protection training for over four years at the time, and their line manager had not completed it for nearly four years also. The watchdog found that these incidents reflected wider weaknesses in MPS policies, procedures, and assurance arrangements for handling sensitive personal information.

    In light of these findings, the ICO issued an enforcement notice and a reprimand to the MPS, emphasizing the need for effective training, monitoring, and assurance mechanisms to protect sensitive personal information. The Met has been given 12 months to improve its compliance with data protection training requirements, aiming for 100 percent completion and following up with staff who miss the deadline.

    The ICO also stated that organizations, particularly those in the public sector handling sensitive law enforcement information, must have effective safeguards in place to protect people's personal information. It added that policies and reminders are not enough if they are not followed, checked, and enforced.

    This incident highlights a broader issue of inadequate data protection practices within some law enforcement agencies. As such, it emphasizes the need for better training and awareness programs, particularly when dealing with sensitive and high-risk information.

    In response to these incidents, the Met has committed to improving its data protection policies, procedures, and assurance arrangements. The force has also acknowledged that there were shortcomings in its handling of personal data and has taken steps to address them.

    In conclusion, the recent data breaches involving the London Metropolitan Police Service underscore the importance of robust data protection practices within law enforcement agencies. The ICO's actions serve as a reminder that organizations must prioritize the protection of sensitive personal information and take proactive measures to prevent such incidents from occurring in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/LONDON-METROPOLITAN-POLICE-SERVICE-RECOGNIZES-DATA-BREACHES-WITH-HANDLING-OF-VICTIMS-PERSONAL-INFORMATION-ehn.shtml

  • https://www.theregister.com/security/2026/08/05/london-cops-handed-victims-new-address-and-number-to-her-stalker-watchdog-says/5283382


  • Published: Wed Aug 5 09:07:45 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us