The Ministry of Defence (MoD) experienced a significant data breach where the names and details of more than 19,000 people were leaked. This breach occurred when an unnamed official emailed a spreadsheet outside the government team processing Afghan relocation applications, leading to the data entering the public domain. The leak was discovered in August 2023 when names of individuals who applied to move to the UK appeared on Facebook. Many Afghans now fear retribution from the Taliban, and the MoD has stated it will not provide compensation or proactively give payouts to those affected. The breach has led to significant distress and worries for the affected families, who are seeking relocation to safer countries.
Source: https://www.bbc.com/news/articles/c20pd5035vyo
TPRM report: https://scoringcyber.rankiteo.com/company/uk-ministry-of-defence
"id": "uk-707072025",
"linkid": "uk-ministry-of-defence",
"type": "Breach",
"date": "7/2025",
"severity": "100",
"impact": "",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'customers_affected': '19,000+ Afghans',
'industry': 'Defence',
'location': 'UK',
'name': 'UK Ministry of Defence',
'type': 'Government'}],
'attack_vector': 'Email',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '19,000+',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal details'},
'date_detected': '2023-08',
'date_publicly_disclosed': '2023-08',
'description': 'The names and details of more than 19,000 people were leaked, '
'with many Afghans now saying they fear retribution from the '
'Taliban.',
'impact': {'brand_reputation_impact': 'Significant',
'data_compromised': 'Personal details of 19,000+ people',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential lawsuits'},
'initial_access_broker': {'entry_point': 'Email',
'high_value_targets': 'Afghan individuals'},
'investigation_status': 'Ongoing',
'motivation': 'Unknown',
'post_incident_analysis': {'root_causes': 'Improper email handling'},
'references': [{'source': 'BBC'}],
'regulatory_compliance': {'legal_actions': 'Potential lawsuits'},
'threat_actor': 'Unnamed official',
'title': 'Data Breach of Afghan Personal Details by UK Ministry of Defence',
'type': 'Data Breach',
'vulnerability_exploited': 'Improper email handling'}