London cops handed victim's new address and number to her stalker, watchdog says
Jump to main content
Search
REG AD
Security
London cops handed victim's new address and number to her stalker, watchdog says
Met ordered to improve safeguards after two preventable data breaches
Connor Jones
Connor<br>Jones
Cybersecurity reporter
Published<br>wed 5 Aug 2026 // 14:30 UTC
UPDATED The UK's data protection regulator has criticized London's Metropolitan Police Service (MPS) after its officers handed a victim's stalker details about her new phone number and home address, among other failures.<br>The Information Commissioner's Office (ICO) today issued the MPS with an enforcement notice [PDF] and a reprimand over the two incidents, which occurred in 2024.<br>Enforcement notices include specific steps offending organizations must take to meet their data protection duties under UK law, while reprimands serve as official warnings concerning breached data protection laws.
REG AD
The ICO outlined two major incidents that were caused by failures at the MPS, but added that they were not isolated and "reflected wider weaknesses in MPS policies, procedures, and assurance arrangements for handling sensitive personal information."
REG AD
The first involved a man subject to an interim Stalking Protection Order (SPO), which restricted him from contacting his victim.<br>An MPS superintendent authorized an application for an interim SPO in January 2024 concerning a man who had been arrested the previous year on suspicion of harassment and malicious communications offences.<br>The man was also, at the time, subject to bail conditions that included a prohibition on contacting the victim and their friends and family.<br>As a result of the man's actions, the unnamed victim had to change her phone number and home address.<br>Despite warnings that all personal information had to be redacted from the copy handed to the defendant, officers included unredacted witness statements and other documents.<br>These exposed the new address and phone number of the victim, and those of her friends and family members.<br>Within days, after the man fled the UK, breaching his bail conditions, the victim reported to the MPS that the defendant had contacted her on her new phone number.<br>A full SPO was issued in May 2024, and the stalker was arrested in July upon re-entering the UK. He was later charged with stalking offenses and imprisoned following a guilty plea.
REG AD
The second incident was a classic CC-not-BCC email blunder, exposing the addresses of 18 people connected to the UK Parliament who had been targeted in a honeytrap operation by "a malicious actor."
MORE CONTEXT
To BCC or not to BCC – that is the question data watchdog wants answered
Council in UK's City of York outs hundreds of disabled residents with a single email blunder
ICO chief John Edwards steps back as workplace probe quietly unfolds
Water company's leaky security earns near-£1M fine
The MPS emailed those affected by the honeytrap scheme to update them about the date by which the suspect would have to answer bail, but forgot to use the BCC function, exposing the target's email addresses to one another.<br>The MPS reported the breach that day, acknowledging that recipients might be able to deduce one another's identities from their email addresses, although three of the accounts had recently been deactivated.<br>The MPS told the Information Commissioner that there was "no reported detriment" as a result of the breach and no official complaints made, although it was aware that "some" targets were "displeased" that their names had been shared.<br>One MP raised the issue in the House of Commons.<br>The ICO said that regarding the honeytrap scheme, the officer who sent the email had not completed data protection training for over four years at the time, and their line manager had not completed it for nearly four years also.<br>The ICO found that data protection training completion rates were low across the force, and the MPS has committed to improving them.<br>Jo Stones, group manager of civil and cyber investigations at the ICO, said: "People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely.
REG AD
"In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people's personal information. One breach exposed a stalking victim's new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation.<br>"These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced."<br>The Met now...