Met Police Exposes Email Addresses of 140 Alleged Al Fayed Victims in Basic CC Blunder

Scotland Yard sent a routine investigation update and accidentally revealed survivors' identities to each other, in a force already under formal enforcement action for data protection failures.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial shot of a dimly lit corporate server room with rows of glowing blue and amber rack lights, a slightly out-of-focus enterprise dat
Share

Key points

  • The Metropolitan Police accidentally revealed the email addresses of roughly 140 women connected to the sexual abuse investigation into Mohamed Al Fayed on 11 August.
  • The error occurred because officers used CC (copying all recipients openly) instead of BCC (blind carbon copy, which hides each recipient's address from the others) in a mass email.
  • The police force has self-reported to the Information Commissioner's Office, the UK's data privacy watchdog.
  • Victim Joanna Brittan says her address was exposed to 42 other survivors, and that the Met had previously promised this kind of breach would never happen again.
  • The ICO issued the Metropolitan Police a formal reprimand and enforcement notice on 5 August over two separate, unrelated data breaches.

The Metropolitan Police sent a routine monthly update about a live sexual abuse investigation. Every recipient could see every other recipient's email address. The reason: someone used CC instead of BCC.

CC, short for "carbon copy", shares each recipient's email address with everyone else on the list. BCC, or "blind carbon copy", hides them. It is one of the oldest and most avoidable mistakes in email.

What happened, exactly?

Around 140 women who signed up for updates from Operation Cornpoppy, the Met's investigation into people who may have helped or enabled serial sexual offending by the late Harrods owner Mohamed Al Fayed, received an email on 11 August. That email also told them three more suspects in their 70s and 80s had been interviewed under caution, bringing the total to seven.

Because officers did not use BCC, recipients could see the email addresses of dozens of others on the list. The force says it split the full group into smaller sub-groups before sending, so addresses were only exposed within each sub-group, not across all 140 women. That is a partial mitigation, but it does not change what happened.

Joanna Brittan, a 61-year-old from Devon who has waived her right to anonymity, told the BBC she could see 42 other survivors' addresses in the email she received. Each of those addresses identified its owner as someone connected to a highly sensitive criminal investigation into sexual abuse.

"It's very shocking because they were meant to have learned all lessons and it would never happen again," Brittan said. She had previously accepted compensation from the Met after officers mistakenly sent sensitive details of her first police interview to two people in Australia.

Should the women affected be worried?

Their email addresses are now held by other people they did not choose to share them with. That alone is a privacy violation, and it signals to anyone who received the email that the other recipients are alleged victims of sexual abuse.

In practical terms, anyone who received the email should be alert to unexpected contact from unfamiliar addresses, whether that is a stranger reaching out on the pretext of the investigation, or unwanted messages of any kind. If something feels wrong, report it to the police and to the ICO.

Dame Jasvinder Sanghera, an advocate for survivors of alleged Al Fayed abuse, said she heard from many women who "feel violated by the police in a space where there is already a lack of confidence in the police investigation."

A pattern, not a one-off

This breach sits inside a larger pattern. On 5 August, six days before this incident, the ICO issued the Metropolitan Police a reprimand and enforcement notice over two separate data failures, one of which involved an officer disclosing a stalking victim's new address and phone number to her alleged stalker. The ICO found "serious and ongoing shortcomings" in data protection training across the force.

The Met says it has referred itself to the ICO over the Operation Cornpoppy breach and is reviewing how it sends updates to victims.

Date Event
2017 Joanna Brittan first reports allegations to Devon and Cornwall Police
2024 Criminal allegations concerning Al Fayed formally added to Operation Cornpoppy
5 August 2025 ICO issues reprimand and enforcement notice over two unrelated Met breaches
11 August 2025 Met sends CC email exposing roughly 140 survivors' addresses
11 August 2025 Met contacts all affected recipients and self-reports to ICO

An apology arrived five hours after the email went out, according to survivors. Dame Jasvinder Sanghera called it "insipid" and said it was "just not good enough."

The Met has confirmed the incident is recorded in its investigation files, that it will monitor the impact on affected women, and that it is considering alternative ways to send updates that reduce the chance of human error. That last point should have been on the agenda before August 11.

© 2026 Threat Vectr