TechNewsReel
Live

Met Police leak email addresses of 140 Mohamed Al-Fayed abuse accusers

A 'human error' during an investigation update exposed the identities of survivors to other recipients.

TechNewsReel Newsroom · August 15, 2026

The Metropolitan Police has apologized after inadvertently disclosing the email addresses of approximately 140 women who accused the late Mohamed Al-Fayed of sexual abuse. The breach occurred during a routine communication update, exposing the identities of survivors in a high-profile investigation.

The incident took place on August 11 during a monthly update for 'Operation Cornpoppy,' the Met's investigation into individuals who may have facilitated or enabled the offending of the former Harrods owner. According to the force, the breach was caused by 'human error' when officials used the 'CC' field instead of 'BCC' in an email distribution, making the recipients' addresses visible to others in their respective groups.

A pattern of failure

This lapse comes at a time of intense scrutiny regarding the Met's data handling capabilities. Just six days prior to this incident, on August 5, the Information Commissioner's Office (ICO) issued a reprimand and an enforcement notice to the force. The ICO cited 'serious and ongoing shortcomings' in data protection training, highlighting a previous case in which the address of a stalking victim was leaked directly to their stalker.

Impact on survivors

For the victims involved in the Al-Fayed case, the breach is more than a technical error. Anonymity is often critical for the safety and psychological wellbeing of survivors of sexual abuse and trafficking. The disclosure has sparked outrage among those who had signed up for the monthly updates to stay informed about the progress of the investigation.

Joanna Brittan, a survivor, described the incident as "more of the same" and called the breach "deeply re abusive." Dame Jasvinder Sanghera, an advocate for survivors, noted that many women felt "violated by the police" in a context where confidence in the investigation was already fragile.

Regulatory oversight

Following the discovery of the error, the Metropolitan Police referred itself to the ICO for further investigation. While the force has issued an apology, the self-referral triggers a formal review of whether the Met breached data protection laws.

Observers will be watching to see if the ICO imposes further sanctions, given the force's recent history of data mismanagement. It remains to be seen how the Met will restructure its internal training to prevent similar failures in cases involving highly sensitive survivor information.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.