Met Police leak email addresses of 143 alleged Mohamed Al Fayed victims
A failure to use BCC in a monthly update email has compromised the identities of survivors in a high-profile abuse investigation.
The Metropolitan Police have accidentally disclosed the email addresses of 143 people who alleged they were sexually abused by the late Harrods owner, Mohamed Al Fayed. The breach occurred during a routine monthly update sent to individuals who had opted in to receive information regarding the ongoing investigation.
The disclosure happened when the force failed to use the blind carbon copy (BCC) function, leaving the recipients' email addresses visible to others within their distribution groups. A Metropolitan Police spokesperson attributed the incident to "human error." In response to the leak, the Met has issued an apology and referred itself to the Information Commissioner's Office (ICO).
Investigation into 'Enablers'
The emails were part of Operation Cornpoppy, a specific police investigation focused on identifying and investigating those who facilitated or enabled Al Fayed's offending. Al Fayed, who died in 2023, has been the subject of more than 400 claims of sexual misconduct spanning from 1977 to 2014.
This incident follows a pattern of data management failures within the force. On August 5, the ICO issued a reprimand and enforcement notice to the Metropolitan Police, citing "serious and ongoing shortcomings" in data protection training and other unrelated breaches. The latest leak suggests that previous warnings regarding the force's handling of sensitive information have not been fully integrated into operational practices.
Impact on Survivors
The breach is particularly severe given the vulnerability of the affected group. Jen Mills and Lindsay Mason, co-chairs of the Justice for Fayed and Harrod Survivors group, noted that providing information to the police is often the hardest step for survivors, only for them to discover their identities were exposed to strangers.
Survivor Joanna Brittan described the event as "very shocking," noting that the police were expected to have learned from previous mistakes to ensure such a breach would not recur. The exposure of these identities erodes trust in a process where survivors had already expressed a lack of confidence in the investigation's handling.
Next Steps
Attention now turns to the ICO's review of the self-referral. While the Met has apologized, the regulatory body will likely examine whether this breach constitutes a further systemic failure in the force's data protection protocols. It remains to be seen if the ICO will impose additional sanctions or mandate stricter oversight of Operation Cornpoppy's communications to prevent further compromises of victim anonymity.