© Copyright Acquisition International 2026 - All Rights Reserved.

Article Image - HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people
Posted 9th December 2020

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

Law firm accuses taxman of ‘breath-taking incompetence’ over catalogue of data loss incidents affecting tens of thousands of members of the public.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

HMRC under fire for 11 ‘serious’ personal data breaches affecting over 20,000 people

data breach

HM Revenue and Customs (HMRC) has reported 11 ‘serious’ personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

The incidents, disclosed in HMRC’s newly published annual report, are estimated to have affected 23,173 people in total and have been analysed by litigation practice Griffin Law.

The most widespread and serious personal data incident recorded in the report happened in May this year at the height of lockdown, when National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

However, the most severe incident occurred in February 2020, when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Name, contact details and ID data, such as passwords and usernames, were leaked, and an estimated 573 people are said to have been impacted as a result.

According to the report, which was released on the 5th of November, the affected customers had not yet been contacted, but the incident is still under investigation.

Other data incidents documented by HMRC in their annual report include a cyber attack against an agent and their client data, affecting 25 people; an incorrectly accessed tax payer record, and resulting refund to the taxpayer’s mother; leak of addresses and property details due to usage of the incorrect Excel spreadsheet, and, leak of medical documents, private correspondence and company data due to paperwork being left on a train.

A further 3,616 ‘centrally managed’ security incidents were also recorded; however specific details of these incidents were not revealed.

HMRC stated the following in the report: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyse all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents. For example, by making changes to business processes relating to post moving throughout HMRC and undertaking assurance work with third party service providers to ensure that agreed processes are being carried out.”

 

Cyber security expert Tim Sadler, CEO, Tessian commented:

“Human error is the leading cause of data breaches today. And given that people are in control of more data than ever before, it’s also not that surprising that security incidents caused by human error are rising. 

“That’s not to say, though, that people are the weakest link when it comes to data security. Mistakes happen – it’s human nature – but sometimes these mistakes can expose data and cause significant reputational and financial damage. It’s an organisation’s responsibility, then, to ensure that solutions are put in place to prevent mistakes that compromise cybersecurity from happening – alerting people to their errors before they do something they regret.” 

 

Donal Blaney, principle, Griffin Law added:

“Taxpayers have a right to expect their sensitive personal data to kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtakingly incompetence”.

Categories: Legal


You Might Also Like
Read Full PostRead - Eye Icon
Autonomous Technology Can Mitigate the Business Impact of the Coronavirus
Innovation
12/03/2020Autonomous Technology Can Mitigate the Business Impact of the Coronavirus

The coronavirus has exposed the soft underbelly of critical infrastructure and industrial sites worldwide – workforce availability. As more and more companies implement business continuity plans to deal with the outbreak, fewer and fewer employees are able t

Read Full PostRead - Eye Icon
What lessons has the pandemic taught us about the fluidity of labour in the run up to Brexit?
Innovation
25/11/2020What lessons has the pandemic taught us about the fluidity of labour in the run up to Brexit?

So much time and angst has been spent on the B word since May 2016, much of it around the issue of fluidity of labour across borders. But what this year has shown is that technology and talent refuse to recognise borders: try building a wall in the cloud. So m

Read Full PostRead - Eye Icon
What Can You Use A Business Administration Degree For?
Leadership
23/12/2020What Can You Use A Business Administration Degree For?

Investing in education is always a wise decision. Many opportunities open up when you become more educated. A business administration degree emphasizes planning, administration, leadership skills, and other aspects involved in running or managing a company.

Read Full PostRead - Eye Icon
Pamplona Capital Management Acquires Controlling Interest in Latham Pool Products
Finance
03/01/2019Pamplona Capital Management Acquires Controlling Interest in Latham Pool Products

Pamplona Capital Management (“Pamplona”), is pleased to announce that it has acquired a controlling interest in Latham Pool Products, Inc. (“Latham” or “the Company”) from Wynnchurch Capital (“Wynnchurch”), which will remain a significant inves

Read Full PostRead - Eye Icon
Government Creates New Business to Save Up to £105 Million in IT Costs
Strategy
20/03/2015Government Creates New Business to Save Up to £105 Million in IT Costs

A new joint venture business has been created to host government computer servers.Crown Hosting Data Centres is a new joint venture between the government and the SME Ark Data Centres Limited, and will provide public bodies with a physical space to host their

Read Full PostRead - Eye Icon
Ones to Watch for 2016: The Best Fraud Investigation Firms
Legal
18/05/2016Ones to Watch for 2016: The Best Fraud Investigation Firms

PLMJ is one of Portugal’s leading law firms and a key player in the country’s legal sector because of its dynamism, capacity for innovation and quality of service.

Read Full PostRead - Eye Icon
UK Bridging Loan Market Set for Further Growth
Finance
19/01/2026UK Bridging Loan Market Set for Further Growth

The UK bridging loans market is continuing its strong rise and is expected to reach around £12.2 billion in outstanding loans this year. This marks another year of expansion following record growth in recent periods, when the total value of the bridging

Read Full PostRead - Eye Icon
Almost Two Thirds of UK Companies Report Higher Revenues Than Last Year
Finance
16/04/2015Almost Two Thirds of UK Companies Report Higher Revenues Than Last Year

64% of UK companies have reported higher or much higher revenues than a year ago, in a new survey commissioned by American Express.

Read Full PostRead - Eye Icon
A Deep-Dive into Mergers & Acquisitions in the Age of Mass Tort
News
07/08/2023A Deep-Dive into Mergers & Acquisitions in the Age of Mass Tort

Mergers and acquisitions are a part of business growth, with the former allowing businesses to join arms to increase their financial muscle power. In contrast, the latter allows businesses to buy out their competition or diversify. While they come with advanta



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have a number of unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow