The Metropolitan Police has issued a formal apology following a data breach that inadvertently exposed the email addresses of approximately 140 people who have reported sexual abuse by the late Harrods owner, Mohamed Al Fayed. The incident occurred on August 11 when the force sent a monthly update regarding Operation Cornpoppy—the ongoing investigation into individuals who may have enabled Al Fayed’s alleged offending.
Scotland Yard confirmed that the breach was caused by human error, as staff failed to use the blind copy (BCC) function when emailing the group. Instead, recipients were able to see the email addresses of others within their specific distribution cohort. The force stated that while the recipients were divided into smaller groups, the privacy of those involved was still compromised.
The update itself contained significant developments in the investigation, revealing that three additional suspects, all in their 70s and 80s, have been interviewed under caution. This brings the total number of individuals interviewed as part of the probe to seven. Previously, the Met reported that 154 victims had come forward with allegations connected to the late businessman.
In response to the error, a spokesperson for the Metropolitan Police stated, “Due to human error, recipients’ email addresses were visible to others on the distribution list. The issue was identified quickly and immediate action was taken.” The force confirmed that every affected individual was contacted directly on the same day the breach occurred.
The Metropolitan Police has referred itself to the Information Commissioner’s Office (ICO) to address the data protection failure. Officials noted that the incident has been formally recorded in the investigation’s files, and the force is currently reviewing its internal processes to prevent a recurrence. This includes exploring alternative communication methods that minimize the risk of human error.
“We understand the impact this may have on victims and sincerely apologise,” the spokesperson added. “The incident is being investigated as a matter of priority, and we are reviewing our processes to help prevent a similar breach from happening again.” The force is also considering providing further support and additional safeguards for those impacted.
Despite the breach, the police emphasized that supporting survivors remains the central focus of Operation Cornpoppy. The force remains committed to providing regular updates to those involved in the investigation and will continue to monitor the circumstances and the broader impact of this disclosure.
The Metropolitan Police has apologised after it inadvertently disclosed email addresses of around 140 people who say they were sexually abused by the late Harrods owner Mohamed Al Fayed.














