A data breach at the UK Ministry of Defence in February 2022 exposed the personal details of approximately 19,000 Afghan citizens who had assisted British forces, as well as some senior British officials and spies. The leak, which was not discovered until part of the list was published online in August 2023, resulted in the Taliban targeting those named, leading to direct threats, home raids, and, in many cases, the deaths of family members and colleagues. Research by Refugee Legal Support, supported by UK academics, found that 49 individuals reported losing family or colleagues due to the breach, and nearly 100 reported direct threats to their own lives. The majority of those affected have not been offered relocation to the UK, leaving them and their families at continued risk.
The Information Commissioner's Office fined the Ministry of Defence £350,000 for a previous, smaller breach in 2021, but the 2022 incident is considered one of the UK's most damaging data protection failures. The Taliban have used the leaked information to systematically hunt down those who aided Western forces, with 87 percent of surveyed victims reporting personal risks and over 100 reporting home raids. The UK government responded by securing a super-injunction to limit reporting on the breach, but the ongoing intimidation, violence, and lack of adequate support for those affected highlight the severe human cost of the incident.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
The UK Ministry of Defence experienced a data breach involving information related to Afghans, exposing affected people to serious risk. Reporting on the incident emphasizes human consequences including fear, beatings, and killings tied to the leak.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.