READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

UK Parliament Committee: MoD's Afghan Data Breach Was a Foreseeable Failure, Not a Fluke

UK Parliament Committee: MoD's Afghan Data Breach Was a Foreseeable Failure, Not a Fluke
A Commons Defence Committee inquiry found the Ministry of Defence's 2023 leak of more than 18,500 Afghan Arap applicants' data resulted from systemic failures, not one person's mistake, and that a near two-year super-injunction shielded the department from accountability. The MoD says the leak should never have happened.

A British parliamentary inquiry has concluded that the 2023 data breach exposing personal details of more than 18,500 Afghans who applied to relocate to the UK was not an isolated incident but a systemic failure.

The Commons Defence Committee published its report Thursday, laying out how a Ministry of Defence staffer shared an Excel spreadsheet with a "trusted third party" and exposed data on every person who had applied to the Afghan Relocations and Assistance Policy scheme by January 2022, according to the BBC. Arap was created in April 2021 to help Afghans who had worked alongside British forces and feared Taliban retaliation. The scheme closed in July 2025.

The BBC previously reported the breach originated from UK Special Forces headquarters. This was one leak among 19 reported between February 2022 and November 2023, the committee found. The pattern reflects a department with no functioning data protection culture.

The committee's language is blunt: the breach was a "foreseeable systemic failure" driven by "inappropriate tools, weak operating procedures, insufficient training, poor organisational continuity, and an inadequate culture of data protection and accountability." Committee chairman Tan Dhesi didn't soften it either. "The Ministry of Defence should stick to defence," he said. "It should never have been left to run immigration casework schemes."

The MoD is built to fight wars, not process visa-style casework for tens of thousands of civilians fleeing a collapsed government. Handing a defense bureaucracy an immigration function it wasn't structured for, and then relying on something as basic as Excel spreadsheets to manage sensitive personal data, appears reckless in hindsight and, per this report, should have appeared reckless at the time too.

The Secrecy Problem

The breach came to light in August 2023. The public didn't learn about it until July 2025, almost two years later, because of a super-injunction, a court order so restrictive it barred media outlets from even confirming the order existed.

That's an extraordinary legal tool to deploy against reporting on a government's own failure. The report found the injunction was originally expected to last four months. It stretched to nearly two years. Dhesi said the length of that gag order "imposed serious costs on accountability and trust."

The MoD's argument for secrecy deserves consideration: some Afghan applicants named in the leaked data were still in Afghanistan, at real risk of Taliban reprisal if the Taliban learned who had applied to work with the British. Suppressing coverage to avoid tipping off the Taliban about who to target is not unreasonable on its face. National security and the safety of vulnerable people are legitimate reasons for a government to seek confidentiality.

But the committee's report suggests the secrecy went well beyond protecting those individuals. Parliamentarians themselves weren't given a confidential briefing on the breach, which the committee specifically questioned, noting that then-Defence Secretary Grant Shapps had pushed back against plans to tell then-shadow defence secretary John Healey. If protecting at-risk Afghans was the goal, there's no obvious reason MPs on the Defence Committee, operating under standard confidentiality rules, couldn't have been informed while the broader public reporting was still restricted. Keeping elected officials in the dark about a major government failure looks less like operational security and more like avoiding scrutiny.

What the MoD Says Now

A Ministry of Defence spokesperson told the BBC the leak "should never have happened" and said the department welcomed the chance to learn from the incident. The standard response from any department caught in a failure, it doesn't undo 18,500 people's data being exposed, and it doesn't answer why the same ministry whose Special Forces headquarters produced this breach was also the one running an immigration casework program the committee called "utterly and obviously inadequate."

The committee's report doesn't allege criminal wrongdoing, and no charges or disciplinary actions have been announced publicly as a result of this specific inquiry. It does establish, based on the government's own data and testimony gathered by MPs, a pattern of repeated breaches, outdated tools, thin training, and a legal strategy that prioritized silence over transparency for far longer than originally planned.

The open question now is whether the MoD actually changes how it handles sensitive personal data, or whether Parliament's report becomes another document that gets cited in hearings and then filed away. The committee wants immigration casework functions moved out of the MoD's hands entirely. Whether the government acts on that recommendation, and how it addresses the other breaches reported over that same period, has not yet been addressed by ministers on the record.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

left
BBCInquiry finds MoD Afghan data breach was foreseeable failure