MPS apologises after email addresses of 143 Al Fayed abuse survivors exposed

The Metropolitan Police Service has apologised after accidentally exposing the email addresses of 143 people who have reported sexual abuse by former Harrods owner Mohamed Al Fayed.

Aug 17, 2026

The addresses were visible to other recipients of a monthly update about Operation Cornpoppy, the Met investigation into allegations against Al Fayed and people suspected of facilitating or enabling his offending.

The force said the disclosure was the result of “human error”, and that the issue was identified quickly. It said all those affected had been contacted and the incident had been referred to the Information Commissioner’s Office.

The Met said the incident was being investigated as a matter of priority and that its processes were being reviewed to prevent a similar breach.

Leigh Day, which represents more than 50 women who report abuse by Al Fayed and people associated with him, said the breach had further undermined survivors’ confidence in the investigation.

Sean Humber, a partner specialising in data breaches at the firm, said the sensitivity of the information and the number of people affected made it a “serious breach of data protection law” and said the Met was likely to face a significant fine from the ICO.

Emma Jones, a human rights partner at Leigh Day, said clients believed the incident demonstrated a lack of care and respect towards survivors and renewed the firm’s call for a public inquiry into the scandal, including the Met’s handling of allegations when they were first reported.

Operation Cornpoppy was launched in November 2024. Seven people have so far been interviewed under caution as part of the investigation, with no arrests made.

The Met said its investigation remained ongoing.

The latest incident comes shortly after the ICO took enforcement action against the MPS over two unrelated data breaches.

The ICO found the incidents were not isolated mistakes but highlighted broader shortcomings in the force’s data protection arrangements. It found low compliance with mandatory data protection training, with one officer and their line manager having gone almost four years without completing the required training.

The enforcement notice requires the MPS to improve its data protection training, monitoring and governance within three and 12 months.

Related News

Select Vacancies

Chief Constable

Staffordshire PFCC

Assistant Chief Constables

South Wales Police

Deputy Chief Constable

Essex Police

Copyright © 2026 Police Professional