A Bulk Email Meant For 18 People, Visible To All 18

The Metropolitan Police Service sent one email to warn 18 people linked to the UK Parliament about a change to a suspect's bail date, and in doing so told each of them who the other 17 were.

The recipients had all been targeted in 2024 and 2025 by someone using WhatsApp messages to gather compromising information on them, a case the Information Commissioner's Office (ICO), the UK's data protection authority, calls the "Honeytrap matter." An MPS officer placed every recipient's email address in the "To" field instead of a hidden field, so each person could see every other name and address on the list. The body of the email said nothing explicit about why the group had been contacted, but the context alone let anyone on it infer highly sensitive information about everyone else.

The Second Breach Was Worse: A Stalking Victim's New Address

A second MPS failure, investigated in the same case, put a stalking victim back in danger from the person she had moved to escape.

An officer serving documents in a Stalking Protection Order case failed to redact confidential third-party information before handing them to the defendant. The papers disclosed the victim's new address and phone number, plus the names and contact details of three witnesses. The victim had changed both specifically because of the risk the defendant posed. He later contacted her on the new number and told her he had received her new details from the MPS itself.

Not Isolated Mistakes: What the ICO Found Underneath

The ICO's investigation found both breaches shared a root cause: weak training compliance, monitoring and governance, not two unlucky one-off errors.

The officer who sent the bulk email had not completed mandatory data protection training in more than four years, and the line manager who should have caught the mistake had gone without it for almost as long. The MPS itself acknowledged that force-wide completion rates for its mandatory Managing Information training were too low. In the stalking case, the ICO also found the officers involved had not received the specialist training required for handling Stalking Protection Order documents, and the process for preparing and checking those documents was inadequate.

The Fix Any Business Can Copy Today

The ICO ordered the MPS to fix its training compliance, monitoring and governance within three and twelve months, and the more useful lesson for any other organisation is what it did not do: it did not accept a policy document as proof the problem was solved.

MPS had already introduced a behavioural alert tool that warns staff when an email is about to go out to multiple external recipients, the same kind of safeguard most business email platforms already offer their administrators and simply have not switched on. Any business that emails groups of clients, patients or case contacts together, in HR, healthcare, legal or professional services, carries the identical risk the MPS just demonstrated: one person forgetting to use a hidden field, and one manager who never checked. One detail is worth noting for private-sector readers rather than public bodies: the ICO issued a reprimand and enforcement notice here, not a monetary fine, consistent with its stated approach of rarely fining public authorities since a fine simply moves money between parts of government. A private company making the same mistake would not get the same treatment.