Last updated 1 month ago
The United Kingdom City of York Council exposed the email addresses of hundreds of disabled residents who hold Blue Badges for accessible parking. The incident occurred when a council employee sent a bulk email to Blue Badge holders but placed all recipients in the To field instead of using the BCC (blind carbon copy) function. The disclosure was reported on June 5, 2026, with no discovery date provided.
The breach resulted from a misconfiguration during email distribution, where the BCC field was not used, causing all recipients' email addresses to be visible to each other. No other data types were compromised, and no threat actor was involved. The attack vector is classified as misconfiguration, as the failure to use BCC exposed the email addresses.
No post-incident details were provided in the article regarding regulatory action, litigation, or remediation steps.
Email sent with recipients in the To field instead of BCC, exposing email addresses of Blue Badge holders to each other
The City of York Council's email blunder highlights the critical need for automated safeguards in bulk email systems, such as mandatory BCC enforcement or recipient address masking. Organizations handling sensitive personal data, especially government agencies, should implement technical controls to prevent human error in email distribution, including pre-send validation checks and staff training on data protection protocols.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector