Last updated 1 month ago
Plymouth City Council, a local government authority in the United Kingdom, disclosed a data exposure incident in June 2026. The breach involved a mass email sent to families registered for home-schooling, where the recipients' email addresses and home addresses were inadvertently exposed due to the use of CC instead of BCC. The incident was reported to the Information Commissioner's Office (ICO), and the council issued an apology.
The attack vector was a misconfiguration in email distribution, specifically the failure to use blind carbon copy (BCC) when sending a bulk email. This resulted in the unintended disclosure of personal data, including email addresses and home addresses, to all recipients. No external threat actor or ransomware group was involved; the breach was caused by human error in email handling.
The council reported the incident to the ICO, the UK's data protection regulator, and issued a public apology. No further details on regulatory action, litigation, or remediation milestones were provided in the article.
Email sent to multiple recipients using CC instead of BCC, exposing email addresses
This incident underscores the critical need for automated controls in email distribution systems, such as enforcing BCC-only for bulk communications or implementing pre-send validation checks. Plymouth City Council's failure to use BCC in a mass email to home-schooling families exposed personal data, highlighting that even simple misconfigurations can lead to regulatory scrutiny and reputational damage. Organizations handling sensitive personal data should implement technical safeguards to prevent human error in email composition.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector