© Copyright Acquisition International 2026 - All Rights Reserved.

Article Image - HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people
Posted 9th December 2020

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

Law firm accuses taxman of ‘breath-taking incompetence’ over catalogue of data loss incidents affecting tens of thousands of members of the public.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

data breach

HM Revenue and Customs (HMRC) has reported 11 ‘serious’ personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

The incidents, disclosed in HMRC’s newly published annual report, are estimated to have affected 23,173 people in total and have been analysed by litigation practice Griffin Law.

The most widespread and serious personal data incident recorded in the report happened in May this year at the height of lockdown, when National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

However, the most severe incident occurred in February 2020, when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Name, contact details and ID data, such as passwords and usernames, were leaked, and an estimated 573 people are said to have been impacted as a result.

According to the report, which was released on the 5th of November, the affected customers had not yet been contacted, but the incident is still under investigation.

Other data incidents documented by HMRC in their annual report include a cyber attack against an agent and their client data, affecting 25 people; an incorrectly accessed tax payer record, and resulting refund to the taxpayer’s mother; leak of addresses and property details due to usage of the incorrect Excel spreadsheet, and, leak of medical documents, private correspondence and company data due to paperwork being left on a train.

A further 3,616 ‘centrally managed’ security incidents were also recorded; however specific details of these incidents were not revealed.

HMRC stated the following in the report: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyse all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents. For example, by making changes to business processes relating to post moving throughout HMRC and undertaking assurance work with third party service providers to ensure that agreed processes are being carried out.”

 

Cyber security expert Tim Sadler, CEO, Tessian commented:

“Human error is the leading cause of data breaches today. And given that people are in control of more data than ever before, it’s also not that surprising that security incidents caused by human error are rising. 

“That’s not to say, though, that people are the weakest link when it comes to data security. Mistakes happen – it’s human nature – but sometimes these mistakes can expose data and cause significant reputational and financial damage. It’s an organisation’s responsibility, then, to ensure that solutions are put in place to prevent mistakes that compromise cybersecurity from happening – alerting people to their errors before they do something they regret.” 

 

Donal Blaney, principle, Griffin Law added:

“Taxpayers have a right to expect their sensitive personal data to kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtakingly incompetence”.

Categories: Legal


You Might Also Like
Read Full PostRead - Eye Icon
6 Basic Principles of a Successful Business Trip
Corporate Social Responsibility
07/09/20226 Basic Principles of a Successful Business Trip

if you travel frequently or are going on business trips for the first time, this article is for you. We have prepared 6 tips for those who want to make a business trip routine a pleasant journey.

Read Full PostRead - Eye Icon
Charities Urged to Provide Better Payment Methods
Finance
22/11/2016Charities Urged to Provide Better Payment Methods

More than one in three people say they are more likely to give money to charity in the festive season.

Read Full PostRead - Eye Icon
Immigration and the Brexit Debate
Finance
03/06/2016Immigration and the Brexit Debate

Immigration is one of the most hotly debated topics in the lead up to the EU referendum, not least because of the uncertainty surrounding the UK’s ongoing relationship with the EU post-Brexit.

Read Full PostRead - Eye Icon
Innovations In the Printing Industry
Innovation
18/05/2022Innovations In the Printing Industry

Technology is increasingly replacing many old techniques of operation and project management. Print and design are two examples of industries undergoing transitions and developments.

Read Full PostRead - Eye Icon
Closing The Gender Gap In Cybersecurity Could Boost UK Economy By £12.6bn
Leadership
20/03/2020Closing The Gender Gap In Cybersecurity Could Boost UK Economy By £12.6bn

Increasing the number of women working in cybersecurity could boost the UK economy by £12.6 billion according to a new report from Tessian, the human layer security company. The report also reveals that closing the 24% gender pay gap in the UK cybersecurity i

Read Full PostRead - Eye Icon
Organisational security and the hidden risk
Strategy
20/01/2021Organisational security and the hidden risk

The security needs of businesses vary greatly dependent on the sector they are in. Despite the varying requirements, each business’ broader approach to security should follow a similar format where vital assets – those that needs to be protected - are surr

Read Full PostRead - Eye Icon
6 Ways You Can Track Employee Hours Online
Strategy
18/01/20216 Ways You Can Track Employee Hours Online

Employee tracking provides accurate logging of employee hours, giving smarter insights not only into projected labor costs but also into employee efficiency and productivity. Accurate employee hours allow employers to generate more accurate payroll numbers to

Read Full PostRead - Eye Icon
Exceptional ehotel Services
Innovation
05/10/2020Exceptional ehotel Services

Corporate travel is something that businesses may have to undertake several times a week, month, or year, depending on the size and internationality of its work. When travelling that much, finding the perfect platform for hotel booking is absolutely imperative

Read Full PostRead - Eye Icon
Leading Lebanese Accounting Firm Secures Success
Finance
13/01/2020Leading Lebanese Accounting Firm Secures Success

Having been named Lebanon’s leading taxation and assurance consultancy of the year in Acquisition International, Sarkis Sakr & Partners has secured its status as one of the country’s foremost accounting practices. Following the firm’s win in Acquisition



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have a number of unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow