© Copyright Acquisition International 2026 - All Rights Reserved.

Article Image - HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people
Posted 9th December 2020

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

Law firm accuses taxman of ‘breath-taking incompetence’ over catalogue of data loss incidents affecting tens of thousands of members of the public.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

data breach

HM Revenue and Customs (HMRC) has reported 11 ‘serious’ personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

The incidents, disclosed in HMRC’s newly published annual report, are estimated to have affected 23,173 people in total and have been analysed by litigation practice Griffin Law.

The most widespread and serious personal data incident recorded in the report happened in May this year at the height of lockdown, when National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

However, the most severe incident occurred in February 2020, when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Name, contact details and ID data, such as passwords and usernames, were leaked, and an estimated 573 people are said to have been impacted as a result.

According to the report, which was released on the 5th of November, the affected customers had not yet been contacted, but the incident is still under investigation.

Other data incidents documented by HMRC in their annual report include a cyber attack against an agent and their client data, affecting 25 people; an incorrectly accessed tax payer record, and resulting refund to the taxpayer’s mother; leak of addresses and property details due to usage of the incorrect Excel spreadsheet, and, leak of medical documents, private correspondence and company data due to paperwork being left on a train.

A further 3,616 ‘centrally managed’ security incidents were also recorded; however specific details of these incidents were not revealed.

HMRC stated the following in the report: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyse all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents. For example, by making changes to business processes relating to post moving throughout HMRC and undertaking assurance work with third party service providers to ensure that agreed processes are being carried out.”

 

Cyber security expert Tim Sadler, CEO, Tessian commented:

“Human error is the leading cause of data breaches today. And given that people are in control of more data than ever before, it’s also not that surprising that security incidents caused by human error are rising. 

“That’s not to say, though, that people are the weakest link when it comes to data security. Mistakes happen – it’s human nature – but sometimes these mistakes can expose data and cause significant reputational and financial damage. It’s an organisation’s responsibility, then, to ensure that solutions are put in place to prevent mistakes that compromise cybersecurity from happening – alerting people to their errors before they do something they regret.” 

 

Donal Blaney, principle, Griffin Law added:

“Taxpayers have a right to expect their sensitive personal data to kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtakingly incompetence”.

Categories: Legal


You Might Also Like
Read Full PostRead - Eye Icon
Coeur Acquisition of Wharf Gold Mine
M&A
27/02/2015Coeur Acquisition of Wharf Gold Mine

Coeur Acquisition of Wharf Gold Mine Coeur Mining, Inc, a precious metals mining company listed on the Toronto and New York Stock exchanges, has acquired the Wharf gold mine located in Lead, South Dakota. The acquisition involved entering into a definitive ag

Read Full PostRead - Eye Icon
Maximizing Your Online Presence: Unleashing the Power of Google Ads for Business Growth
News
06/11/2023Maximizing Your Online Presence: Unleashing the Power of Google Ads for Business Growth

In today’s digital age, establishing a strong online presence is essential for businesses looking to thrive and expand. With countless potential customers turning to the internet to find products and services, it’s crucial to leverage effective dig

Read Full PostRead - Eye Icon
New Export Guide to Help SMEs as They Plan to Grow Globally
Leadership
04/03/2015New Export Guide to Help SMEs as They Plan to Grow Globally

Small and Medium sized businesses (SMEs) are planning to increase exports by 5% in the year ahead.

Read Full PostRead - Eye Icon
Valuation Knows no Boundaries
Innovation
31/07/2016Valuation Knows no Boundaries

PEM Corporate Finance is an M&A and business valuations firm based in Cambridge, England. We’re part of Kreston International – the 10th largest global network of independent accounting firms. We advise SMEs on M&A, buyouts, business valuations, succession

Read Full PostRead - Eye Icon
5 Questions To Ask Before Putting AI Into Practice And A Checklist For Success
Innovation
03/01/20205 Questions To Ask Before Putting AI Into Practice And A Checklist For Success

Despite the power of Artificial Intelligence to transform the customer experience, many AI projects fail at the first hurdle. Henry Jinman at EBI.AI outlines the 5 most common mistakes and how to avoid them using a tried and tested checklist.

Read Full PostRead - Eye Icon
Ambient Advertising, Yard Signs, and More: Why Real-World Marketing Still Matters
News
11/04/2022Ambient Advertising, Yard Signs, and More: Why Real-World Marketing Still Matters

Marketing is essential for every business, but with the popularity of ecommerce, digital marketing has been receiving all the attention. However, we still live in a physical world where people walk into businesses and pass by physical locations. Therefore, eve

Read Full PostRead - Eye Icon
Beacon Rail Enters into an Agreement to Acquire Ascendos Rail Leasing
M&A
13/05/2016Beacon Rail Enters into an Agreement to Acquire Ascendos Rail Leasing

Beacon Rail Leasing (“Beacon”), a leading Pan-European rolling stock lessor, is pleased to announce that it has entered into an agreement to acquire Ascendos Rail Leasing S.à r.l. (“Ascendos”), a European locomotive and rolling stock leasing company.

Read Full PostRead - Eye Icon
Risk Management on the Road: Why Emergency Driver Training Protects Businesses from Costly Exposure
Legal
29/01/2026Risk Management on the Road: Why Emergency Driver Training Protects Businesses from Costly Exposure

In discussions around road safety, businesses often focus on insurance compliance, fleet maintenance, and regulatory requirements. Yet one of the most underestimated contributors to road-related risk is driver response during high-stress, unexpected events. Em

Read Full PostRead - Eye Icon
How to Lower Your Car Insurance Payments Fast
Finance
12/01/2023How to Lower Your Car Insurance Payments Fast

Everyone would like to lower the cost of their car insurance payments. However, not everybody actually looks at active ways to reduce the cost of their auto insurance. If that’s you, it’s time to change your ways. So, check out the following helpful advice



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have a number of unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow