© Copyright Acquisition International 2026 - All Rights Reserved.

Article Image - HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people
Posted 9th December 2020

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

Law firm accuses taxman of ‘breath-taking incompetence’ over catalogue of data loss incidents affecting tens of thousands of members of the public.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

data breach

HM Revenue and Customs (HMRC) has reported 11 ‘serious’ personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

The incidents, disclosed in HMRC’s newly published annual report, are estimated to have affected 23,173 people in total and have been analysed by litigation practice Griffin Law.

The most widespread and serious personal data incident recorded in the report happened in May this year at the height of lockdown, when National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

However, the most severe incident occurred in February 2020, when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Name, contact details and ID data, such as passwords and usernames, were leaked, and an estimated 573 people are said to have been impacted as a result.

According to the report, which was released on the 5th of November, the affected customers had not yet been contacted, but the incident is still under investigation.

Other data incidents documented by HMRC in their annual report include a cyber attack against an agent and their client data, affecting 25 people; an incorrectly accessed tax payer record, and resulting refund to the taxpayer’s mother; leak of addresses and property details due to usage of the incorrect Excel spreadsheet, and, leak of medical documents, private correspondence and company data due to paperwork being left on a train.

A further 3,616 ‘centrally managed’ security incidents were also recorded; however specific details of these incidents were not revealed.

HMRC stated the following in the report: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyse all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents. For example, by making changes to business processes relating to post moving throughout HMRC and undertaking assurance work with third party service providers to ensure that agreed processes are being carried out.”

 

Cyber security expert Tim Sadler, CEO, Tessian commented:

“Human error is the leading cause of data breaches today. And given that people are in control of more data than ever before, it’s also not that surprising that security incidents caused by human error are rising. 

“That’s not to say, though, that people are the weakest link when it comes to data security. Mistakes happen – it’s human nature – but sometimes these mistakes can expose data and cause significant reputational and financial damage. It’s an organisation’s responsibility, then, to ensure that solutions are put in place to prevent mistakes that compromise cybersecurity from happening – alerting people to their errors before they do something they regret.” 

 

Donal Blaney, principle, Griffin Law added:

“Taxpayers have a right to expect their sensitive personal data to kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtakingly incompetence”.

Categories: Legal


You Might Also Like
Read Full PostRead - Eye Icon
Legal Advice and Procedures for Co-Parenting Arrangements
News
29/08/2023Legal Advice and Procedures for Co-Parenting Arrangements

Co-parenting is a concept that has evolved to accommodate the diverse dynamics of modern families. Traditionally, divorced or separated parents establish separate households for their children, with scheduled visitation periods. However, a new approach known a

Read Full PostRead - Eye Icon
Working Together Keeps Port in High  Demand
Strategy
26/06/2017Working Together Keeps Port in High Demand

Taylor’s is celebrating its 325th this year. For many, Taylor’s is the archetypal Port house and its wines are the quintessential Ports. Established over three centuries ago in 1692, Taylor’s is one of the oldest of the founding Port houses. Dedicated en

Read Full PostRead - Eye Icon
2016’s Most Innovative Hedge Fund Manager, UK
Strategy
30/06/20162016’s Most Innovative Hedge Fund Manager, UK

AIM is a UK-based asset manager, founded in 2008 by a long-standing team that had formerly managed $6 billion at UBS and $2 billion at Insight.

Read Full PostRead - Eye Icon
How to Securely Invest in Businesses That Do Well During a Pandemic
Finance
21/07/2021How to Securely Invest in Businesses That Do Well During a Pandemic

The Covid-19 pandemic has caused immeasurable harm to businesses. However, there are some that are thriving. Find out where best to invest now.

Read Full PostRead - Eye Icon
Eurozone’s Exit from Deflation ECB a Pause for Breath
Finance
01/05/2015Eurozone’s Exit from Deflation ECB a Pause for Breath

Annual consumer price inflation across the Eurozone climbed up to zero in April 2015 after four months of consecutive declines, Eurostat reported this morning.

Read Full PostRead - Eye Icon
Dogecoin is the new GameStop – Are investors going to get burned?
Finance
21/04/2021Dogecoin is the new GameStop – Are investors going to get burned?

Dogecoin has become the new GameStop, with frenzied trading potentially going to deliver a bloody nose to novice investors, warns the CEO of one of the world’s largest independent financial advisory and fintech organisations.

Read Full PostRead - Eye Icon
What works best: HTML email marketing or plain text?
News
15/06/2022What works best: HTML email marketing or plain text?

Email marketing is a powerful tool to reach more people, increase engagement, and generate more leads. There are two ways to send an email to your marketing list, one is to spruce it up using HTML and the other is to keep is simple with plain text. Which one w

Read Full PostRead - Eye Icon
Reaching Out to Your Target Audience: Three Ways to Use Social Media Effectively
News
09/02/2022Reaching Out to Your Target Audience: Three Ways to Use Social Media Effectively

Social media has evolved in many ways that online networking platforms are no longer considered just tools to connect with family and friends.

Read Full PostRead - Eye Icon
Strategic Maintenance Decisions in Modern Fleets: Why Fuel System Management Matters to Business Performance
Legal
29/01/2026Strategic Maintenance Decisions in Modern Fleets: Why Fuel System Management Matters to Business Performance

For organisations that operate vehicle fleets or rely on vehicles to deliver services, maintenance decisions are business decisions. They directly affect operational continuity, cost control, safety performance, and legal exposure. Fuel system maintenance, par



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have a number of unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow