Met Police leak email addresses of 143 Mohamed Al Fayed abuse victims
A 'human error' during a police update email exposed the contact details of survivors in a high-profile sexual abuse investigation.
The Metropolitan Police have inadvertently disclosed the email addresses of 143 people who reported being sexually abused by the late Mohamed Al Fayed. The breach occurred during a routine communication, raising fresh concerns over the force's ability to protect highly sensitive survivor data.
The leak happened on August 11 during a monthly update email for 'Operation Cornpoppy,' an investigation focused on individuals who facilitated or enabled Al Fayed's offending. According to a Met Police spokesperson, the breach was caused by "human error" when officers used the 'CC' field instead of 'BCC,' making the recipients' email addresses visible to others within their distribution groups. The force stated that the issue was identified quickly and immediate action was taken. The Met has since apologised and referred the incident to the Information Commissioner's Office (ICO).
A Pattern of Failure
This incident follows a string of data protection failures within the Metropolitan Police. Just days prior, on August 5, the ICO reprimanded the force for "serious and ongoing shortcomings" in its data protection training and governance. That reprimand included a separate, severe incident in which the personal details of a stalking victim were leaked directly to their stalker.
The breach occurs against the backdrop of a massive investigation into the former Harrods owner. More than 400 claims of sexual misconduct, spanning from 1977 to 2014, have been made against Al Fayed, making the protection of witness and victim anonymity a critical component of the legal process.
Impact on Survivors
For survivors of sexual abuse, the exposure of their identity and contact information can be devastating. Dame Jasvinder Sanghera, an advocate for survivors, noted that many victims felt "violated by the police" in a context where confidence in the investigation was already fragile. Joanna Brittan, an alleged victim, described the breach as "shocking," noting that the police were expected to have learned from previous mistakes to ensure such an event would never happen again.
Industry experts suggest that such breaches can be "re-abusive," potentially deterring other victims from coming forward in high-profile cases due to a lack of trust in police confidentiality.
Next Steps
The ICO is now reviewing the incident as part of its broader oversight of the Met's data handling practices. It remains to be seen whether this latest failure will trigger further sanctions or mandatory structural changes to how the Metropolitan Police manages sensitive distribution lists. The force continues to pursue Operation Cornpoppy to identify those who enabled Al Fayed's alleged crimes.