Met Police expose email addresses of 140 Mohamed Al Fayed abuse survivors
A failure to use BCC in a police update has compromised the identities of victims in a sensitive sexual abuse investigation.
The Metropolitan Police have inadvertently disclosed the email addresses of approximately 140 people who reported sexual abuse by the late Harrods owner Mohamed Al Fayed. The breach occurred on August 11, compromising the privacy of survivors during a routine communication update.
The incident took place during a monthly update for 'Operation Cornpoppy,' an investigation targeting individuals who facilitated or enabled Al Fayed's offending. According to a Met Police spokesperson, the disclosure was the result of "human error," specifically a failure to use the blind carbon copy (BCC) function, which left recipients' addresses visible to others in their distribution groups. The update in question informed survivors that three additional suspects, aged in their 70s and 80s, had been interviewed under caution, bringing the total number of interviewed suspects to seven.
Systemic Data Failures
This breach follows a period of intense scrutiny regarding the Met's handling of personal data. Just six days prior to this incident, on August 5, the Information Commissioner's Office (ICO) issued a formal reprimand and an enforcement notice to the force. That action concerned unrelated breaches but highlighted "serious and ongoing shortcomings" in the Metropolitan Police's data protection training. In response to the Operation Cornpoppy leak, the Met has apologized and referred itself to the ICO for further investigation.
Impact on Survivors
The exposure of this information is particularly critical given the nature of the crimes involved. Jen Mills and Lindsay Mason, co-chairs of the Justice for Fayed and Harrods Survivors group, noted that reporting these crimes is often the hardest thing survivors ever do, only for them to discover their identities were exposed to strangers. Survivor Joanna Brittan, who stated her email was disclosed to 42 other survivors, described the event as "shocking," noting that the force was expected to have learned from previous mistakes.
Future Oversight
As the ICO reviews the self-referral, the Met Police faces mounting pressure to prove it can safely manage highly sensitive survivor information. The focus now remains on whether the force can implement the training mandated by the ICO's August 5 notice to prevent further systemic failures. It remains to be seen if the ICO will levy additional sanctions following this latest lapse in protocol.