Wednesday, August 05, 2026

Damning report reveals “foreseeable failure” behind Afghanistan data breach, calls for accountability

July 30, 2026
3 mins read
Damning report reveals “foreseeable failure” behind Afghanistan data breach, calls for accountability

Report reveals Ministry of Defence data breach exposed personal details of Afghans

A catastrophic Ministry of Defence data breach that exposed the personal details of tens of thousands of Afghans was a “foreseeable failure,” a damning investigation has concluded, reports BritPanorama.

According to a report from the influential defence select committee, MPs condemned the government’s handling of the data breach, including the resulting superinjunction—a court order so stringent that even acknowledging its existence was prohibited—and the covert evacuation of thousands of Afghan families.

The committee stated that “secrecy was maintained for too long, accountability was too weak, delivery was too fragmented, and affected Afghans were too often left without the information and support they needed.”

The breach, which occurred in February 2022, revealed the details of 18,700 Afghans who reported being in danger from the Taliban due to their ties to UK forces and sought escape to Britain.

This error prompted an unprecedented superinjunction affecting national media including The Independent and initiated a secret evacuation programme, the overall cost of which remains unclear but likely runs into billions of pounds.

After the revelation by various outlets in July of the hidden operation, MPs established an inquiry to scrutinise the circumstances. Their report highlighted several critical failures:

  • The data breach could have been prevented with basic Excel training for Ministry of Defence (MoD) personnel.
  • By August 2023, when the leak was discovered, thousands were already aware that a significant data incident had occurred.
  • The government failed to find “the right balance between operational secrecy and democratic accountability,” and the superinjunction was maintained for too long.
  • The secrecy denied affected Afghans the opportunity to protect themselves and caused delays to the evacuation programme.
  • Thousands of Afghans eligible for relocation to Britain remain trapped in Afghanistan as the government has not clarified how it plans to assist in their evacuation.

MPs urged the government to issue periodic reassessments of risks facing Afghan applicants for UK resettlement schemes, calling for annual reporting of findings. They also demanded a clear policy on assistance for eligible Afghans who have not yet been evacuated.

The committee requested that the MoD clarify who was responsible for data protection risks before this breach, highlighting a lack of accountability within the civil service.

The data breach occurred when a member of MoD staff sent an Excel file outside the government, mistakenly believing it contained details for around 150 Afghan applicants; hidden within the file were the details of over 18,500 others. The report concluded that this breach “could still have been prevented” with basic training.

As of June 9, 2026, approximately 7,000 individuals remained eligible for relocation to the UK, of which around 3,700 are believed to be in Afghanistan.

In April, the MoD informed Afghan families approved for sanctuary in Britain that they would need to flee the Taliban-run country independently. This led to a “two-tier system,” where some who can finance their own relocation could leave, while vulnerable families struggle.

MPs expressed concern about inadequate government explanations regarding the protection of eligible Afghans unable to travel safely, lawfully, or affordably for UK entry-clearance checks, identifying a significant gap in the current policy framework.

Tan Dhesi MP, chair of the defence committee, remarked, “The latest ‘self-move’ policy risks excluding people the UK has promised to help, including some who should have been brought here years ago.”

The broader implications are alarming. Dhesi emphasised that the MoD’s responsibilities should not extend to managing immigration casework schemes, criticizing the excessive use of secrecy as shielding against accountability.

Person A, an independent caseworker who alerted the government to the data breach in summer 2023, called for the reinstatement of third-party support for Afghan families trying to escape. “It is immoral to make our promise to resettle these families contingent on their ability to secure large loans at short notice,” they stated.

Professor Sara de Jong, from the Sulha Alliance, which aids Afghans who worked for the British army, welcomed the committee’s push for assistance for those unable to evacuate. She asserted that “the human costs, from physical risk to psychological damage, are much more significant than the government initially accepted.”

Additionally, she affirmed that the government’s prolonged secrecy around the data breach reflected a lack of public accountability and increased risk for affected Afghans, noting that the assumptions regarding trustworthiness were overly pessimistic.

A MoD spokesperson acknowledged the significant impact of the incident and stated, “This incident should never have happened.” They assured that thousands of eligible Afghans have been safely relocated and affirmed the commitment to concluding the Afghan Resettlement Programme by the end of the current parliament, reporting that important reforms, including enhanced data protection standards and improved governance, are in place.

The fallout continues to encapsulate a complex interaction of accountability, morality, and practicalities surrounding support for vulnerable Afghans. It raises persistent questions about the efficacy of the government’s resettlement approach amidst a landscape marked by secrecy and operational failures.

Leave a Reply

Your email address will not be published.

Don't Miss

Report reveals serious failings in UK’s treatment of Afghan special forces applications

Report reveals serious failings in UK’s treatment of Afghan special forces applications

There were “serious failings” in how the Ministry of Defence handled applications
Teachers' contact details compromised in cyber attack on Department for Education

Teachers’ contact details compromised in cyber attack on Department for Education

Data breach at Department for Education exposes thousands of records The names