The Metropolitan Police has apologised and referred itself to the Information Commissioner’s Office after sending a routine case update to 143 survivors of Mohamed Al Fayed’s alleged abuse — and leaving every recipient’s email address visible to everyone else on the list. No hacker, no malware, no exploited vulnerability. Just a monthly update email sent to the “To” or “CC” field instead of “BCC”. Lawyers for the survivors say the force is now likely facing a significant ICO fine, on top of the reputational damage of re-traumatising the people the email was meant to reassure.

It’s a headline-grabbing story because of who’s involved, but the mistake itself is depressingly ordinary. Misdirected email — including the CC/BCC mix-up specifically — has been one of the most commonly reported causes of data breaches to the ICO for years, well ahead of most types of cyberattack. It happens because it’s easy to do and easy to miss: one wrong click in a field most people barely look at before hitting send.

Why this keeps happening to organisations that should know better

The pattern is always the same. Someone needs to email a group of people who don’t know each other and shouldn’t see each other’s details — clients, patients, complainants, job applicants, tenants — and the sender defaults to muscle memory rather than checking the recipient field. It’s especially common with recurring updates like the Met’s monthly case notes, precisely because routine tasks are where attention lapses. The more sensitive the list, the worse the consequences: exposing 143 abuse survivors’ identities to each other isn’t just a data protection breach on paper, it’s a real safety and trust issue for the people involved.

Any UK business that emails groups of customers, clients, or service users sits closer to this risk than it probably realises. A law firm updating a group of claimants, a healthcare provider messaging a patient list, a charity contacting beneficiaries, an HR team emailing a group of candidates — all of it carries the same exposure if BCC isn’t used correctly, or if a spreadsheet of email addresses gets pasted into the wrong field.

Reducing the risk in your own business

Default bulk email to a proper tool, not your inbox. Email marketing and CRM platforms send each recipient an individually addressed email by design — there’s no BCC field to forget because there’s no shared recipient list to expose. If you’re regularly emailing groups of clients, this is worth setting up even for small numbers.

If you must use BCC manually, build in a check. A second person confirming the recipient field before send, or a brief pause before hitting send on any group email, catches the mistake that a rushed, routine task otherwise sails past.

Know your 72-hour clock. Under UK GDPR, a breach involving personal data that risks people’s rights and freedoms must generally be reported to the ICO within 72 hours of you becoming aware of it. The Met’s self-referral was the right instinct — a business that spots its own BCC mistake and stays quiet risks a far worse outcome if it surfaces later.

If your business handles sensitive client or case data regularly and wants a proper incident-response plan rather than hoping it never happens, KeepSafe monitors for exactly this kind of exposure and helps businesses respond fast when something does go wrong. And if your email processes are still built around manual habit rather than a proper system, CoolCoding can help set up the technical guardrails that make this mistake structurally harder to make.

The takeaway

The most damaging data breach at your business probably won’t be a sophisticated attack — it’ll be an ordinary email sent to the wrong field on a day nobody was paying close enough attention. Check how your business sends group emails today, before it’s the story.