A massive personal data leak in February 2022 involving the UK’s Ministry of Defence (MoD) resulted in the exposure of personal information of nearly 19,000 Afghan nationals who had applied for the Afghan relocations and assistance policy (ARAP). The breach occurred when a defence official mistakenly emailed a spreadsheet containing the names and personal details of the applicants outside of official government systems. The leak has endangered the lives of the individuals and their families, as the Taliban, now in power, is known to hunt down those who supported the US-led coalition. The breach was discovered more than a year later when excerpts of the dataset were anonymously posted to a Facebook group. A small number of people named on the list are known to have been subsequently killed, although it is unclear if this was a direct result of the data breach.
Source: https://cybernews.com/news/afghanistan-united-kingdom-data-leak/
TPRM report: https://scoringcyber.rankiteo.com/company/uk-ministry-of-defence
"id": "uk-810071625",
"linkid": "uk-ministry-of-defence",
"type": "Breach",
"date": "7/2025",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Defence',
'location': 'United Kingdom',
'name': 'Ministry of Defence (MoD)',
'type': 'Government'}],
'attack_vector': 'Email',
'data_breach': {'number_of_records_exposed': '18,700',
'personally_identifiable_information': 'Names of applicants',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal information'},
'date_detected': 'August 2023',
'date_publicly_disclosed': 'April 2024',
'description': 'A massive personal data leak in the British military exposed '
'the personal information of nearly 19,000 Afghan nationals '
'who applied for the Afghan relocations and assistance policy '
'(ARAP). The leak occurred in February 2022 and was detected '
'in August 2023.',
'impact': {'data_compromised': 'Personal information of 18,700 applicants'},
'initial_access_broker': {'entry_point': 'Email',
'high_value_targets': 'Afghan nationals assisting '
'British forces'},
'motivation': 'Hunting down people who supported the US-led coalition',
'post_incident_analysis': {'root_causes': 'Careless handling of sensitive '
'information'},
'references': [{'source': 'The Guardian'}],
'threat_actor': 'Taliban',
'title': 'Afghan Nationals Data Leak',
'type': 'Data Breach',
'vulnerability_exploited': 'Careless handling of sensitive information'}