The Intelligence and Security Committee (ISC) experienced a significant data breach affecting up to 100,000 Afghans. The breach occurred when an official mistakenly sent a datasheet containing details of thousands of Afghans, exposing them to potential danger. The breach was kept secret for two years, and the committee was not informed until a superinjunction was lifted. The breach cost the UK taxpayer billions and has led to demands for an inquiry and the release of sensitive papers.
TPRM report: https://scoringcyber.rankiteo.com/company/united-states-senate-select-committee-on-intelligence
"id": "uni611071825",
"linkid": "united-states-senate-select-committee-on-intelligence",
"type": "Breach",
"date": "7/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Up to 100,000 Afghans',
'industry': 'Public Sector',
'location': 'United Kingdom',
'name': 'UK Government',
'type': 'Government'}],
'attack_vector': 'Email',
'data_breach': {'number_of_records_exposed': 'Up to 100,000',
'personally_identifiable_information': 'Names and other '
'personal details',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personally Identifiable '
'Information'},
'date_publicly_disclosed': '2023-10-17',
'description': 'A data breach affecting up to 100,000 Afghans occurred when '
'an official sent an email with a datasheet containing details '
'of thousands of Afghans, exposing them to potential Taliban '
'reprisals.',
'impact': {'brand_reputation_impact': 'Significant',
'data_compromised': 'Personal details of Afghans',
'financial_loss': 'Billions of UK taxpayer money',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential inquiries and legal actions'},
'initial_access_broker': {'entry_point': 'Email',
'high_value_targets': 'Afghans needing evacuation'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Human error and lack of oversight'},
'references': [{'date_accessed': '2023-10-17',
'source': 'The Independent',
'url': 'https://www.independent.co.uk/news/uk/politics/afghan-data-breach-isc-beamish-b2415580.html'}],
'response': {'communication_strategy': 'Lifting of superinjunction and public '
'disclosure'},
'title': 'Afghan Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Human Error'}