The Metropolitan Police has apologised after a data breach exposed the email addresses of more than 140 people who say they were sexually abused by the late Harrods owner Mohamed Al Fayed.
The Met has blamed “human error”, apologised to those affected, and referred itself to the Information Commissioner’s Office (ICO).
What has been reported so far
On 11 August 2026, the Met sent an update to people who had signed up to receive information about Operation Cornpoppy – the investigation into people who may have facilitated or enabled alleged sexual offending by Mohamed Al Fayed.
But when the update was sent, instead of hiding the recipients’ email addresses, they were visible to other people receiving the message.
Reports suggest 143 people were affected.
The Met said it identified the mistake quickly and contacted everyone affected on the same day. It is now investigating what happened and reviewing whether different ways of communicating with victims could reduce the risk of a similar mistake happening again.
This breach is particularly sensitive
An email address may seem like a relatively limited piece of information. But context matters. In this case, receiving the email could identify someone as being connected to an investigation involving allegations of sexual abuse.
Campaigners representing survivors have criticised the breach, arguing that people who come forward about alleged abuse should be able to trust that information identifying them will be properly protected.
The Justice for Fayed and Harrods Survivors group has asked the Met to explain how the incident happened and what additional safeguards are now being introduced.
The Met was already facing scrutiny over data protection
The latest incident comes shortly after the ICO took enforcement action against the Metropolitan Police following two separate data protection failures.
On 5 August 2026, the regulator issued the Met with a reprimand and enforcement notice after finding wider weaknesses in its policies, procedures and safeguards for handling sensitive personal information.
One of those incidents resulted in a stalking victim’s new address and telephone number being disclosed to the person she needed protection from. Another exposed the names and email addresses of 18 people linked to a highly sensitive police investigation.
The ICO said these were not simply isolated mistakes. Its investigation identified wider weaknesses as well as “serious and ongoing shortcomings” in data protection training. The Met has been ordered to improve its training compliance, monitoring and governance arrangements.
The latest breach involving alleged Al Fayed victims happened just days after that enforcement action was announced.
What happens next?
The Met has referred the latest breach to the ICO. At the time of writing, the regulator has not announced whether it will take any further action.
The Met says the incident is being investigated as a priority and that it is reviewing its processes to help prevent a similar breach happening again. It is also considering further support for those affected.
For people who have come forward about deeply personal and distressing experiences, protecting their privacy is particularly important. This incident is another reminder that a data breach is not always the result of a cyberattack. A simple mistake can expose personal information too – and, depending on the circumstances, the impact can be significant.
Join the Claim is monitoring developments and will provide further updates as more information becomes available.
Join the Claim connects consumers with SRA-regulated lawyers. Keep an eye out for updates on any potential claim and possible eligibility checks/registration opportunities.