Metropolitan Police supplier breach exposed details of 47,000 officers and staff
- Organization
- Metropolitan Police Service
- Exploit
- Supply Chain Attack
- Industry
- Law Enforcement
The Metropolitan Police Service disclosed in late August 2023 that an unauthorised party had gained access to the IT systems of a supplier that printed warrant cards and staff passes, potentially exposing details of about 47,000 officers and civilian staff.
The force said the exposed data included names, ranks, photographs, vetting levels and pay numbers, which are payroll reference numbers. It said the supplier did not hold home addresses, telephone numbers or financial account details, so those were not affected. All personnel were notified.
The National Crime Agency was brought in and the Information Commissioner's Office was notified. Investigators were assessing whether the intrusion was a financially motivated ransomware attack or a deliberate attempt to obtain police data. The Met said it had put additional security measures in place after the supplier reported the incident.
Police representatives described significant alarm within the force. Rick Prior, vice chair of the Metropolitan Police Federation, said the incident would cause "incredible concern and anger" among his members. A former Met commander warned that photographs of officers working in undercover, surveillance and counter-terrorism roles could be valuable to organised crime groups or extremists, given the force's national responsibilities for counter-terrorism and diplomatic protection. The Met did not name the supplier in its statements at the time.