The UK Information Commissioner's Office has reprimanded London's Metropolitan Police Service and issued an enforcement notice after two preventable 2024 breaches exposed highly sensitive personal information. In one case, officers handling a Stalking Protection Order shared unredacted witness statements and related documents with the suspect, revealing the victim's new home address and phone number despite protections already being in place.
In a separate incident, the force disclosed the email addresses of 18 people linked to the UK Parliament by sending an update on a honeytrap investigation using CC instead of BCC. The ICO said the incidents pointed to wider failures in the Met's policies, procedures, training, and assurance around data handling, noting that the officer involved in the email breach had not completed data protection training for more than four years; the force has been ordered to improve training compliance, review how staff send emails to multiple recipients, and report progress to the regulator over the next 12 months.

See the reporting duties and controls this puts on the clock.
11 events from the most recent confirmed update back to the earliest known activity.
Earlier in 2026, the ICO served the Metropolitan Police commissioner with a separate enforcement notice over failures under the Freedom of Information Act. This was distinct from the later action over the two personal-data breaches.
The suspect was arrested in July 2024 after re-entering the UK. He later pleaded guilty to stalking offences and was imprisoned.
A full Stalking Protection Order was issued against the suspect in May 2024. This followed the earlier interim order process during which the victim's information was exposed.
Following the Parliament-linked email disclosure, one Member of Parliament raised the breach in the House of Commons. The Met later told the ICO there had been no official complaints, though some targets were displeased their names had been shared.
The Metropolitan Police reported the Parliament-linked email disclosure to the ICO on the same day it occurred. The force acknowledged that recipients could potentially infer one another's identities from their email addresses.
In a separate 2024 incident, the Metropolitan Police sent an update email about a suspect's bail response deadline using CC instead of BCC. This exposed the email addresses of 18 people connected to the UK Parliament who had been targeted in a honeytrap operation.
After fleeing the UK in breach of bail conditions, the suspect contacted the victim on her new phone number. This demonstrated that the improperly disclosed information had reached him.
During the Stalking Protection Order process in 2024, Metropolitan Police officers provided the defendant with unredacted witness statements and related documents. The disclosure exposed the victim's new home address and phone number, along with details of her friends and family members.
In January 2024, a Metropolitan Police superintendent authorized an application for an interim Stalking Protection Order against the suspect. The victim had already changed her phone number and home address because of his actions.
The stalking suspect was arrested in 2023 on suspicion of harassment and malicious communications offences. He was also subject to bail conditions prohibiting contact with the victim and the victim's friends and family.
The UK Information Commissioner's Office issued the Metropolitan Police Service an enforcement notice and a reprimand over the two 2024 data breaches. The regulator said the incidents reflected broader weaknesses in policies, procedures, training, and assurance arrangements for handling sensitive personal information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.