© Copyright Acquisition International 2026 - All Rights Reserved.

Article Image - HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people
Posted 9th December 2020

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

Law firm accuses taxman of ‘breath-taking incompetence’ over catalogue of data loss incidents affecting tens of thousands of members of the public.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

data breach

HM Revenue and Customs (HMRC) has reported 11 ‘serious’ personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

The incidents, disclosed in HMRC’s newly published annual report, are estimated to have affected 23,173 people in total and have been analysed by litigation practice Griffin Law.

The most widespread and serious personal data incident recorded in the report happened in May this year at the height of lockdown, when National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

However, the most severe incident occurred in February 2020, when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Name, contact details and ID data, such as passwords and usernames, were leaked, and an estimated 573 people are said to have been impacted as a result.

According to the report, which was released on the 5th of November, the affected customers had not yet been contacted, but the incident is still under investigation.

Other data incidents documented by HMRC in their annual report include a cyber attack against an agent and their client data, affecting 25 people; an incorrectly accessed tax payer record, and resulting refund to the taxpayer’s mother; leak of addresses and property details due to usage of the incorrect Excel spreadsheet, and, leak of medical documents, private correspondence and company data due to paperwork being left on a train.

A further 3,616 ‘centrally managed’ security incidents were also recorded; however specific details of these incidents were not revealed.

HMRC stated the following in the report: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyse all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents. For example, by making changes to business processes relating to post moving throughout HMRC and undertaking assurance work with third party service providers to ensure that agreed processes are being carried out.”

 

Cyber security expert Tim Sadler, CEO, Tessian commented:

“Human error is the leading cause of data breaches today. And given that people are in control of more data than ever before, it’s also not that surprising that security incidents caused by human error are rising. 

“That’s not to say, though, that people are the weakest link when it comes to data security. Mistakes happen – it’s human nature – but sometimes these mistakes can expose data and cause significant reputational and financial damage. It’s an organisation’s responsibility, then, to ensure that solutions are put in place to prevent mistakes that compromise cybersecurity from happening – alerting people to their errors before they do something they regret.” 

 

Donal Blaney, principle, Griffin Law added:

“Taxpayers have a right to expect their sensitive personal data to kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtakingly incompetence”.

Categories: Legal


You Might Also Like
Read Full PostRead - Eye Icon
Private Risk Capital Development Advisors, LLC, Leading the way in PPLA and PPA Solutions
Finance
16/06/2020Private Risk Capital Development Advisors, LLC, Leading the way in PPLA and PPA Solutions

When it comes to Private Placement Life Insurance (PPLI) and Private Placement Annuity (PPA), the firm that supports you must be one you trust implicitly. It’s a business where every detail must be tended to with care. The team at Private Risk Capital Develo

Read Full PostRead - Eye Icon
Why Early Evidence Preservation Is a Business Risk Issue After Commercial Vehicle Crashes
Legal
27/01/2026Why Early Evidence Preservation Is a Business Risk Issue After Commercial Vehicle Crashes

The first calls after a commercial vehicle crash are usually practical. Someone alerts a supervisor. Dispatch tries to figure out whether the route can be covered. A customer asks where the load is. The safety manager starts building a timeline from the driver

Read Full PostRead - Eye Icon
Exploring Riding Rules and What Happens When You Crash with A Vehicle
Legal
24/05/2023Exploring Riding Rules and What Happens When You Crash with A Vehicle

The number of motorcycle crashes in Washington is trending upward, as 2022 recorded 125 fatal crashes in the state, with 514 injured. Even though it’s not a motorcycle hub, Federal Way has also recorded hit-and-run cases and several fatalities.

Read Full PostRead - Eye Icon
Bringing the Power of Inference-Based Thinking to all Corners of the Internet
Innovation
22/07/2019Bringing the Power of Inference-Based Thinking to all Corners of the Internet

Mindtrend provides people with the ability to share, explore and connect information in a meaningful, collaborative and machine-verifiable manner with the natural feel of blogging.

Read Full PostRead - Eye Icon
Innovations In Eco-Friendly Business Heating Systems
Innovation
08/09/2023Innovations In Eco-Friendly Business Heating Systems

As the world continues to grapple with environmental concerns, businesses are increasingly exploring innovative ways to align their operations with eco-friendly practices.

Read Full PostRead - Eye Icon
How Much Is a Workers’ Comp Claim Worth in Philadelphia?
News
22/07/2022How Much Is a Workers’ Comp Claim Worth in Philadelphia?

How Much Is a Workers’ Comp Claim Worth in Philadelphia? A workplace injury can have devastating consequences, particularly if you’re unable to return to work swiftly or you sustain long-term damage. Fortunately, most employees in Philadelphia are eligible

Read Full PostRead - Eye Icon
From Fear to Preparedness: Mastering Risk and Process Management
News
06/02/2024From Fear to Preparedness: Mastering Risk and Process Management

In recent years, there has been a significant increase in the demand for combined risk management and process tools.

Read Full PostRead - Eye Icon
Everything You Need to Know Before Entering the Construction Industry
News
25/04/2023Everything You Need to Know Before Entering the Construction Industry

Are you considering a career change and contemplating entering the construction industry? If so, you're in the right place. The construction sector offers a wide range of job opportunities, from manual labour to professional roles, such as architects and engin

Read Full PostRead - Eye Icon
Competition & Antitrust Law: Ensuring Compliance & Avoiding Disputes
Leadership
05/10/2015Competition & Antitrust Law: Ensuring Compliance & Avoiding Disputes

We spoke to Alan H Silberman, Chair-Emeritus of DENTONS antitrust/competition, who lent us his insight and experience as we sought to better understand the ever-evolving landscape of competition law.



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have a number of unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow