MoD data breach was ‘foreseeable’ failure that left Afghans in danger – MPs
The Afghan data breach was a “foreseeable” failure in a system that left people who had worked with UK troops in danger for years, a parliamentary inquiry has found.
In a report published on Thursday, the Commons Defence Committee said the Ministry of Defence (MoD) lacked the expertise to run the UK’s Afghan relocation schemes and had used secrecy as a “shield” against proper accountability.
The inquiry was launched last year after it was revealed the personal data of thousands of Afghans applying for relocation to the UK had been inadvertently disclosed in February 2022, six months after the fall of Kabul to the Taliban.
The discovery of the breach in August 2023, when details of applicants were shared on a Facebook page, sparked the creation of a secret relocation route for those affected.
But an unprecedented superinjunction prevented the breach being made public until July last year, shortly after applications to the Government’s relocation schemes closed.
In its report, the Defence Committee said the breach was not “an individual mistake” but a “foreseeable systemic failure” caused by “inappropriate tools, weak operating procedures, insufficient training, poor organisational continuity, and an inadequate culture of data protection and accountability”.
The breach was one of a string of 19 “data security incidents” reported between February 2022 and November 2023, and was caused by a member of MoD personnel sharing an Excel spreadsheet with a “trusted third party”.
While the spreadsheet was thought to contain data for around 150 applicants to the Afghan Relocations and Assistance Policy (Arap) scheme, it contained hidden data relating to more than 18,500 other applications.
The committee described the MoD’s approach to using Excel as a “continuing cultural failure” and criticised its handling of the wider Afghan relocation schemes as “utterly and obviously inadequate”.
Committee chairman Tan Dhesi said: “The Ministry of Defence should stick to defence – it should never have been left to run immigration casework schemes.”
Mr Dhesi’s committee also criticised the secrecy that surrounded both the breach itself and the role of UK special forces in the resettlement schemes.
Although it was initially expected to last for four months, allowing time for the MoD to respond to the breach without increasing the risk of the data falling into the hands of the Taliban, the superinjunction remained in place for almost two years.
The committee said that while the initial secrecy “may have been justified”, the length of time the injunction was in place “imposed serious costs on accountability and trust”.
The MPs criticised the decision not to provide confidential briefing to parliamentarians, with then-defence secretary Grant Shapps even resisting plans to inform his Labour counterpart John Healey.
The committee noted that the fact the superinjunction was only lifted in July 2025 meant that ministers who may have been “considering their position” over the breach had already left government.
Thursday’s report also criticised the Government’s policy of not commenting on special forces matters, saying it was “inappropriate” when connected to “administrative decision-making” and their role in immigration casework.
Reports have suggested that the initial breach was connected to UK special forces’ involvement in deciding applications for relocations from their Afghan counterparts, the so-called “Triples”.
While the committee did not reach a conclusion about who had sent the email that caused the breach, it said special forces involvement “should not prevent Parliament and the public from understanding how administrative failings occurred”.
Mr Dhesi said: “Secrecy has been too easily used as a shield against proper accountability in areas far removed from sensitive operations.”
The MPs also raised concerns about the handling of the Triples, who had worked closely with UK forces but in hundreds of cases had their applications for resettlement refused.
A review, described as a “major corrective exercise” by the committee, overturned 884 of those refusals.
The committee said the Government now had “a special responsibility to former Triples whose applications were wrongly refused and who, because of those failings and subsequent delay, may have spent additional years in hiding or been left to make their own way to a third country”.
They warned that the extra years in hiding had left many destitute and unable to make their own way out of Afghanistan.
From April 2026, under a so-called “self-move” policy, eligible Afghans have been required to fund their own travel to a third country for checks before being allowed to come to the UK.
The MoD said the change was due to changing levels of risk and value-for-money considerations, with increasing numbers of Afghans moving to safe third countries following the announcement.
Ministers have also imposed a 12-month deadline for reaching that third country, which the committee warned “risks becoming in practice an exclusion mechanism for eligible people who are too poor, too vulnerable or too exposed to travel independently”.
Mr Dhesi said: “This inquiry began with a data breach, but became about the real lives affected by delay, secrecy and flawed decision-making.
“The Government must now explain how it will protect eligible Afghans who cannot safely, lawfully or affordably reach a third country for UK entry-clearance checks.
“Otherwise, the latest ‘self-move’ policy risks excluding people the UK has promised to help, including some who should have been brought here years ago.”
An MoD spokesperson said: “This incident should never have happened and we acknowledge the significant impact it has had on many people.
“Thousands of eligible Afghans have already been safely relocated to the UK, where they can rebuild their lives and we are committed to ensuring that we conclude the Afghan resettlement programme by the end of this Parliament.
“We are learning the lessons from this incident and important reforms are already in place, including improved data protection standards, strengthened case-working processes and better programme governance.
“We welcome the public and parliamentary scrutiny of our actions, so we can learn more and be held to account, and we’ll continue to work closely with the committee on this issue.”
Published: by Radio NewsHub
