ICO fines & breach roundup — 5 August 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. Metropolitan Police Service hit with an enforcement notice and reprimand over mishandled sensitive disclosures
The ICO announced on 5 August 2026 that it had issued the Metropolitan Police Service (MPS) with a reprimand and a formal enforcement notice after two separate incidents in which highly sensitive personal information was wrongly disclosed. In one case, a stalking victim's new contact details were sent to the person she needed protection from. In the other, a bulk email revealed the identities of people connected to a highly sensitive criminal investigation. The ICO found the MPS had failed to put in place the technical and organisational measures required under section 40 of the Data Protection Act 2018, and identified multiple weaknesses in its data-protection training, compliance monitoring and governance. The enforcement notice requires the MPS to fix these gaps within three and twelve months. ICO Group manager Jo Stones said people "entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk," and have "the right to expect that information will be handled securely."
What your business should learn: Both incidents came down to nobody double-checking a recipient before sensitive information went out — a solvable, cheap problem, not a technology failure. If your business ever emails a group of people, publishes a document, or forwards case/customer files, put a second pair of eyes on anything containing personal or sensitive data before it leaves the building: confirm the recipient list is right, confirm attachments are properly redacted, and never let a single person send bulk correspondence involving other people's personal details unchecked. A five-minute review habit is far cheaper than a regulator's enforcement notice.
2. Police National Legal Database (PNLD) breach exposes contact details of 100,000+ officers and staff, reportedly via a misconfigured public web portal
PNLD, the legal-reference service run by West Yorkshire Police and used by all 43 police forces in England and Wales plus other criminal-justice bodies, identified a data security incident on 26 July 2026 and confirmed it publicly in early August after a group calling itself "ExfilSquad" posted stolen data on a dark-web leak site. The exposed data includes the names, organisations and work email addresses of police officers, staff, criminal-justice professionals, government partners and customers, and separately affected "Ask the Police," a public-facing advice site, where the names and email addresses of people who had submitted questions were exposed. PNLD says no confidential information about victims, witnesses or suspects was involved, and the incident is unconnected to national police databases. The breach has been reported to the ICO and the National Crime Agency. Several security researchers, analysing the pattern of the leak, believe the likely cause was a misconfigured Microsoft Power Platform/Power Pages public web portal that allowed anonymous visitors to query backend database tables directly — though PNLD itself has not confirmed this specific technical cause, and it should be treated as a strong working theory rather than a confirmed fact.
What your business should learn: Many small businesses now build customer-facing web forms, booking pages or portals using low-code/no-code tools (Microsoft Power Pages, website-builder plugins, form tools wired to a database or CRM) precisely because they're quick to set up — but "quick to set up" and "safe by default" are not the same thing, and these platforms can expose the data behind the form to anyone if permissions aren't locked down correctly. If you or a supplier has built any public web form that reads from or writes to a database, ask specifically whether anonymous/public users can query records beyond what the form itself displays — most platforms, including Microsoft's own guidance for Power Pages, document exactly how to check and lock this down, and it costs nothing but ten minutes to ask the question.
3. Department for Education breach exposes over 607,000 records after a social-engineering attack on its helpdesk
The Department for Education (DfE) confirmed in late July 2026 that a cyber attack, claimed by a group calling itself "ExfilSquad," had exposed more than 607,000 records via its Help Desk Self-Service Portal and its Turing Scheme portal (which administers funding for international education and training placements). The compromised data is reported to be limited to professional contact details — names, job titles, work email addresses and phone numbers of school leaders, university staff, government officials and other individuals or organisations who had previously contacted the department — and does not include passwords, bank details or other highly sensitive personal data. Industry commentary on the incident has focused on how it was carried out: a social-engineering attack targeting the helpdesk itself, rather than a technical exploit of the underlying systems. The DfE says it is working with the ICO, the National Cyber Security Centre and the National Crime Agency to investigate.
What your business should learn: A helpdesk, support inbox or reception desk is often the softest target in an otherwise well-defended organisation, because its whole job is to be helpful to whoever contacts it. If anyone in your business fields support requests, password resets or account changes by phone or email, give them one fixed rule with no exceptions: verify the requester through an independent channel (call back a known number, use a pre-agreed passphrase) before making any change or sharing any personal data — never rely on someone simply knowing a name, order number or account reference, because that information is exactly what an attacker researches first.
Sources
- ICO — Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures
- Infosecurity Magazine — ICO Reprimands Metropolitan Police for Data Snafu
- The Register — Police National Legal Database confirms data theft after dark web leak
- The Hacker News — PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
- Infosecurity Magazine — UK's Police National Legal Database Reveals Data Breach
- Rescana — PNLD Data Breach Exposes UK Police and Government Contact Information via Microsoft Power Platform Misconfiguration
- Security Affairs — PNLD Confirms Data Breach Affecting UK Police and Justice Staff
- Computer Weekly — Department for Education suffers data breach
- Computing — DfE confirms cyber attack exposed 607,000 records
- IT Security Guru — Experts react as Department for Education cyber attack exposes 607,000 records
- UKAuthority — Social engineering attack hits DfE helpdesk systems