{"id":36074,"date":"2025-08-28T01:37:51","date_gmt":"2025-08-28T01:37:51","guid":{"rendered":"https:\/\/news.godj.com\/news\/mod-staff-were-warned-not-to-share-hidden-data-before-afghan-leak\/"},"modified":"2025-08-28T01:37:51","modified_gmt":"2025-08-28T01:37:51","slug":"mod-staff-were-warned-not-to-share-hidden-data-before-afghan-leak","status":"publish","type":"post","link":"https:\/\/news.godj.com\/news\/mod-staff-were-warned-not-to-share-hidden-data-before-afghan-leak\/","title":{"rendered":"MoD staff were warned not to share hidden data before Afghan leak"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-component=\"text-block\">\n<p class=\"sc-9a00e533-0 hxuGS\">Ministry of Defence staff were warned before the Afghan data leak not to share information containing hidden tabs, according to documents released by the UK&#8217;s data regulator.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Last month it emerged that the details of almost 19,000 people who had applied to move to the UK were leaked when an official emailed a spreadsheet that contained a hidden tab with the information.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Documents released by the Information Commissioner&#8217;s Office (ICO) also show that staff there raised concerns about why the body had not issued a fine to the MoD.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The MoD said they had worked to improve data security, but an ICO spokesperson said the government had not yet done enough to learn the lessons.<\/p>\n<\/div>\n<div data-component=\"text-block\">\n<p class=\"sc-9a00e533-0 hxuGS\">According to an ICO memo, guidance in place at the time of the leak showed that the &#8220;MoD was aware of the risks of sharing data and explicitly referenced the need to remove hidden data from datasets&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Hidden tabs are a common feature in spreadsheet software and make information invisible to the user, but still easily accessible if the settings on a document are changed.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The government estimates that the 2022 leak, which led to an emergency resettlement scheme for people at risk of persecution by the Taliban, will eventually cost around \u00a3850m.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">A super-injunction granted by the High Court in September 2023 prevented the incident being reported for almost two years, before <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cvg8zy78787o\" class=\"sc-f9178328-0 bGFWdi\">the order was lifted last month<\/a>.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Shortly after the MoD became aware of the data breach in 2023, they informed the UK&#8217;s data regulator, the ICO. The two bodies held a number of secret meetings over the next two years and documents published by the regulator reveal some of what was discussed.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">They say that government officials described the leak as likely &#8220;the most expensive email ever sent&#8221;, and internal emails also show that ICO staff raised concerns about why the body had chosen not to independently investigate the MoD or issue a fine.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Data breaches by public bodies must legally be reported to the ICO, which can then decide to investigate and potentially fine the organisation responsible.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">ICO staff privately discussed the potential &#8220;reputational risk&#8221; to the regulator after it chose not to take action against the MoD, despite issuing a \u00a3350k fine for a much smaller Afghan data breach in 2023.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">In an email sent the afternoon before the leak became public, one ICO staff member said their justification for not fining the government was still an &#8220;imperfect answer&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The documents were published by the ICO earlier this month following a Freedom of Information request which was not submitted by the BBC.<\/p>\n<\/div>\n<div data-component=\"text-block\">\n<p class=\"sc-9a00e533-0 hxuGS\">Written notes were forbidden during the secret meetings, but an ICO memo detailing the whole timeline was drawn up after the incident became public just last month.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The memo says the MoD took &#8220;intensive measures to recover and delete data from all identified sources&#8221; and &#8220;limit loss of control&#8221; after the breach was discovered.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">In a private email discussion, one ICO staff member questioned why it was &#8220;taking so long to decide whether to investigate&#8221; and said &#8220;if I was a journalist I would ask why has it taken two years to ascertain whether or not to take action&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Another said the ICO had played a &#8220;significant role&#8221; but said &#8220;the reality is that we have only been able to review information in situ and been reliant on the MoD to gather evidence under our guidance&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Documents show the ICO ultimately decided against sanctioning the MoD because it did not want to &#8220;impose additional cost to the taxpayer&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Last week, <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cp8950pyy1vo\" class=\"sc-f9178328-0 bGFWdi\">BBC News revealed there had been 49 separate data breaches<\/a> in the past four years at the unit handling relocation applications from Afghans seeking safety in the UK.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">An ICO spokesperson said they had &#8220;focused clearly on making sure that the causes of breaches were identified, rectified and lessons learned&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">They said the government had &#8220;not yet done enough to achieve the pace of changes&#8221; required and said they had asked for &#8220;assurances that necessary improvements are being made and standards are being raised&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">An MoD spokesperson said the government had worked to &#8220;improve data security across the department through better software, training and data experts&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">They added: &#8220;We have worked hand-in-hand with the ICO during an internal investigation and accepted all recommendations in full to ensure a similar incident doesn&#8217;t happen again.&#8221;<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.com\/news\/articles\/cwy5e911j37o?at_medium=RSS&#038;at_campaign=rss\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ministry of Defence staff were warned before the Afghan data leak not to share information containing hidden tabs, according to documents released by the UK&#8217;s data regulator. Last month it emerged that the details of almost 19,000 people who had applied to move to the UK were leaked when an official emailed a spreadsheet that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":36075,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51],"tags":[10989,147,4249,4894,11440,2201,123,3847],"class_list":["post-36074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-politics","tag-afghan","tag-data","tag-hidden","tag-leak","tag-mod","tag-share","tag-staff","tag-warned"],"_links":{"self":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/36074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/comments?post=36074"}],"version-history":[{"count":1,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/36074\/revisions"}],"predecessor-version":[{"id":36076,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/36074\/revisions\/36076"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media\/36075"}],"wp:attachment":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media?parent=36074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/categories?post=36074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/tags?post=36074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}