© Copyright Acquisition International 2026 - All Rights Reserved.

Article Image - HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people
Posted 9th December 2020

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

Law firm accuses taxman of ‘breath-taking incompetence’ over catalogue of data loss incidents affecting tens of thousands of members of the public.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

data breach

HM Revenue and Customs (HMRC) has reported 11 ‘serious’ personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

The incidents, disclosed in HMRC’s newly published annual report, are estimated to have affected 23,173 people in total and have been analysed by litigation practice Griffin Law.

The most widespread and serious personal data incident recorded in the report happened in May this year at the height of lockdown, when National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

However, the most severe incident occurred in February 2020, when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Name, contact details and ID data, such as passwords and usernames, were leaked, and an estimated 573 people are said to have been impacted as a result.

According to the report, which was released on the 5th of November, the affected customers had not yet been contacted, but the incident is still under investigation.

Other data incidents documented by HMRC in their annual report include a cyber attack against an agent and their client data, affecting 25 people; an incorrectly accessed tax payer record, and resulting refund to the taxpayer’s mother; leak of addresses and property details due to usage of the incorrect Excel spreadsheet, and, leak of medical documents, private correspondence and company data due to paperwork being left on a train.

A further 3,616 ‘centrally managed’ security incidents were also recorded; however specific details of these incidents were not revealed.

HMRC stated the following in the report: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyse all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents. For example, by making changes to business processes relating to post moving throughout HMRC and undertaking assurance work with third party service providers to ensure that agreed processes are being carried out.”

 

Cyber security expert Tim Sadler, CEO, Tessian commented:

“Human error is the leading cause of data breaches today. And given that people are in control of more data than ever before, it’s also not that surprising that security incidents caused by human error are rising. 

“That’s not to say, though, that people are the weakest link when it comes to data security. Mistakes happen – it’s human nature – but sometimes these mistakes can expose data and cause significant reputational and financial damage. It’s an organisation’s responsibility, then, to ensure that solutions are put in place to prevent mistakes that compromise cybersecurity from happening – alerting people to their errors before they do something they regret.” 

 

Donal Blaney, principle, Griffin Law added:

“Taxpayers have a right to expect their sensitive personal data to kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtakingly incompetence”.

Categories: Legal


You Might Also Like
Read Full PostRead - Eye Icon
Building a Successful Fitness Business
News
17/05/2024Building a Successful Fitness Business

Embarking on a journey to become a professional personal trainer can be as exhilarating as it is transformative. For those aspiring to turn their passion for fitness into a lucrative career, acquiring the right credentials is a crucial step. Choosing to enrol

Read Full PostRead - Eye Icon
Current Approach to Due Diligence  Requires Rethink
M&A
30/04/2015Current Approach to Due Diligence Requires Rethink

Completing a corporate transaction without rigorous financial due diligence is unthinkable. Yet, despite numerous well publicised incidents of cybercrime, investors remain blasé about the potential impact of cyber risks on long term value.

Read Full PostRead - Eye Icon
The Golden Age of Digital Experience Monitoring
Innovation
24/12/2020The Golden Age of Digital Experience Monitoring

In the midst of a pandemic, using cloud-based technology such as Microsoft 365 has proven vital for employees to stay productive. In October 2020, Microsoft reported 115 million daily active users of Teams. This is where Martello Technologies comes in, offerin

Read Full PostRead - Eye Icon
Cargo Spill Motorcycle Accidents: Liability, Risk and Legal Exposure After Freeway Incidents
Legal
27/01/2026Cargo Spill Motorcycle Accidents: Liability, Risk and Legal Exposure After Freeway Incidents

Unsecured or improperly loaded cargo represents a significant risk within commercial transport operations, particularly on high-speed roads. When debris falls from a truck, the consequences can be severe for other road users, especially motorcyclists who have

Read Full PostRead - Eye Icon
Deal Volumes in the Consulting Sector Reach near-peak Conditions
Finance
12/04/2016Deal Volumes in the Consulting Sector Reach near-peak Conditions

2015 was a fantastic year for Consulting sector M&A deals! According to Equiteq’s Global Consulting Mergers & Acquisitions Report 2016, deal activity in the sector grew by 9.4%, continuing an upward trend in deal activity and multiples.

Read Full PostRead - Eye Icon
Cybersecurity seen as the biggest threat to business in Sword GRC Annual Survey of Risk Managers
Leadership
15/01/2019Cybersecurity seen as the biggest threat to business in Sword GRC Annual Survey of Risk Managers

Sword GRC, a supplier of specialist risk management software and services, has published the latest findings from its annual survey of global risk managers. Almost 150 Risk Managers from highly risk-aware organizations worldwide were canvassed for their opinio

Read Full PostRead - Eye Icon
Due Diligence Solutions : Exceeding Clients Expectations
Legal
13/08/2019Due Diligence Solutions : Exceeding Clients Expectations

Due Diligence Solutions is an independent business supporting IFA/Firms to complete their platform and DFM due diligence review.

Read Full PostRead - Eye Icon
What You Need to Know About Microsoft 365 Copilot, the Ultimate AI Assistant
Innovation
25/01/2024What You Need to Know About Microsoft 365 Copilot, the Ultimate AI Assistant

Microsoft 365 Copilot is the new AI powered solution from Microsoft, and it looks set to revolutionise the way we work. Microsoft have this week announced they are removing the 300-seat purchase minimum for commercial plans and making Microsoft 365 Copilot ava

Read Full PostRead - Eye Icon
Leveraging AI for Fraud Detection and Risk Assessment in the FinTech
News
22/01/2024Leveraging AI for Fraud Detection and Risk Assessment in the FinTech

While ChatGPT become lazy recently, denying to perform basic tasks, and making excuses on why it shouldn’t do, what was required, it is still hard to deny that machine learning models can bring many advantages to any technological solution, and FinTech i



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have a number of unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow