In February 2022, the UK Ministry of Defence (MoD) inadvertently leaked the personal details of nearly **19,000 Afghans** who had applied for relocation under the **Afghan Relocations and Assistance Policy (ARAP)**, including individuals like the Afghan special forces veteran (Triples) who worked alongside British forces. The breach exposed biometric data, application statuses, and identities, placing them at severe risk of Taliban retaliation. One affected family, already in Pakistan awaiting resettlement, was detained for deportation back to Afghanistan, where their leaked association with UK forces makes them prime targets for persecution or execution. The Taliban’s claimed amnesty has been widely discredited by UN reports, heightening fears for their safety. The leak not only compromised the security of vulnerable refugees but also undermined trust in the UK’s relocation program, with families now in hiding or facing imminent deportation. The MoD’s failure to secure this data has had life-threatening consequences, as the exposed individuals—including women and children—remain stranded without protection, while the UK’s slow processing of ARAP applications exacerbates their plight.
Source: https://www.bbc.com/news/articles/c776zgj73lpo
TPRM report: https://www.rankiteo.com/company/uk-ministry-of-defence
"id": "uk-122081525",
"linkid": "uk-ministry-of-defence",
"type": "Breach",
"date": "8/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Defense/Military',
'location': 'United Kingdom',
'name': 'UK Ministry of Defence (MoD)',
'type': 'Government Agency'},
{'customers_affected': '19,000+ (Including Afghan '
'Triples, Interpreters, and '
'Families)',
'location': ['Afghanistan', 'Pakistan (Refugees)'],
'name': 'Afghan Relocations and Assistance Policy '
'(ARAP) Applicants',
'size': '~19,000 individuals',
'type': 'Individuals/Families'},
{'customers_affected': 'Multiple families (e.g., case '
"of Rayan's family: 1 detained, "
'others in hiding)',
'industry': 'Defense',
'location': ['Afghanistan',
'Pakistan (Detained/At Risk)'],
'name': "Afghan 'Triples' Special Forces (and "
'Families)',
'type': 'Military Personnel'}],
'customer_advisories': ['None publicly issued by MoD; affected individuals '
'rely on media reports.'],
'data_breach': {'data_exfiltration': ['Unintentional (Leaked by MoD)'],
'file_types_exposed': ['Documents', 'Biometric Records'],
'number_of_records_exposed': '~19,000',
'personally_identifiable_information': ['Full Names',
'Military Roles',
'Family Members',
'Location Data '
'(Pakistan/Afghanistan)'],
'sensitivity_of_data': 'Extremely High (Life-Threatening if '
'Exposed to Taliban)',
'type_of_data_compromised': ['PII (Names, Biometrics)',
'Military Service Records',
'ARAP Application Details',
'Family Associations']},
'date_detected': '2022-02',
'date_publicly_disclosed': '2022-02',
'description': 'A major data breach by the UK Ministry of Defence (MoD) in '
'February 2022 inadvertently leaked the personal details of '
'nearly 19,000 Afghans who had applied for resettlement under '
'the **Afghan Relocations and Assistance Policy (ARAP)**. The '
'leaked data included biometric records and application '
'details of individuals who had worked with British forces in '
'Afghanistan, such as the **Triples (Afghan special forces '
'units)**. The breach has placed these individuals—many of '
'whom are still awaiting relocation decisions—at severe risk '
'of Taliban retaliation, deportation from Pakistan, or '
'targeted violence. One affected family, including children as '
'young as eight months old, has already been detained in '
'Pakistan for imminent deportation to Afghanistan, where their '
'lives are at risk due to their association with UK forces. '
'The breach was confirmed by the BBC, which reviewed leaked '
'documents. The UK MoD has not commented on individual cases '
'but stated its commitment to relocating eligible applicants.',
'impact': {'brand_reputation_impact': ["Damage to UK MoD's Credibility",
'Criticism of Handling of Afghan '
'Allies',
'Public Outcry Over Failed '
'Protections'],
'customer_complaints': ['Fear of Taliban Retaliation',
'Pleas for Protection from Affected '
'Families'],
'data_compromised': ['Personal Identifiable Information (PII)',
'Biometric Data',
'Application Records',
'Military Affiliation Details'],
'identity_theft_risk': ['High (Due to Biometric and PII Exposure)'],
'legal_liabilities': ['Potential Violations of Data Protection '
'Laws (e.g., UK GDPR)',
'Accountability for Endangering Lives'],
'operational_impact': ['Compromised Safety of 19,000+ Afghans',
'Risk of Deportation/Persecution',
'Loss of Trust in UK Relocation Programs']},
'investigation_status': 'Ongoing (No Public Updates on MoD Internal '
'Investigation)',
'lessons_learned': ['Critical need for **secure handling of sensitive data** '
'for at-risk populations (e.g., refugees, military '
'allies).',
'**Delayed relocation processes** exacerbate '
'vulnerabilities for individuals exposed in breaches.',
'Lack of **transparent communication** with affected '
'parties undermines trust in protection programs.',
'**Human error** remains a significant risk in '
'high-stakes data management.'],
'post_incident_analysis': {'corrective_actions': ['MoD has not disclosed '
'specific corrective '
'actions beyond generic '
'commitments to ARAP.',
'Parliamentary scrutiny '
'likely (per MP Bailey’s '
'statements).'],
'root_causes': ['Human error in data handling '
'(e.g., improper sharing/storage '
'of ARAP applicant files).',
'Inadequate **safeguards for '
'high-risk data** (e.g., '
'biometrics of Afghan allies).',
'**Bureaucratic delays** in '
'relocation programs increasing '
'exposure window.']},
'recommendations': ['Immediate **risk assessment** for all 19,000 affected '
'individuals, prioritizing those in imminent danger '
'(e.g., detained families).',
'Accelerate **ARAP processing** with emergency '
'protections for leaked applicants.',
'Implement **strict access controls** and **audit '
'trails** for sensitive refugee/military data.',
'Establish a **dedicated support hotline** for breach '
'victims with legal/relocation assistance.',
'Collaborate with **Pakistani authorities** to halt '
'deportations of at-risk Afghans pending relocation.',
'Public **transparency report** on breach causes and '
'preventive measures.'],
'references': [{'date_accessed': '2023-11-24',
'source': 'BBC News',
'url': 'https://www.bbc.com/news/uk-67501234'},
{'date_accessed': '2023-10 (Referenced in BBC Article)',
'source': "UN Report: 'No Safe Haven'"}],
'regulatory_compliance': {'regulations_violated': ['Potential UK GDPR '
'Non-Compliance',
'Data Protection Act 2018 '
'(UK)'],
'regulatory_notifications': ['No Public Record of '
'ICO (UK Information '
'Commissioner’s '
'Office) Involvement']},
'response': {'communication_strategy': ['Limited Public Statements',
'No Direct Communication to Affected '
'Individuals Confirmed'],
'incident_response_plan_activated': ['MoD Acknowledged Breach '
'(No Public Details on '
'Response Plan)',
'BBC Investigation '
'Triggered Awareness'],
'recovery_measures': ['Ongoing ARAP Processing (Delayed for '
'Many)',
'High Commission Engagement (Per MP '
'Bailey)'],
'remediation_measures': ['MoD Statement on Commitment to '
'Relocate Eligible Applicants',
'No Publicized Technical Fixes'],
'third_party_assistance': ['Labour MP Calvin Bailey (Advocacy)',
"UN Report 'No Safe Haven' "
'(Highlighted Risks)']},
'stakeholder_advisories': ['Labour MP Calvin Bailey: Urged government action '
'to protect Triples and families.',
'UN: Warned against Taliban amnesty claims, citing '
'ongoing persecution risks.'],
'title': "UK Ministry of Defence Data Breach Exposing Afghan Refugees' "
'Details (2022)',
'type': ['Data Breach', 'Unintentional Disclosure', 'Privacy Violation'],
'vulnerability_exploited': ['Human Error',
'Improper Data Handling',
'Lack of Access Controls']}