The Police Services of Northern Ireland has apologised following a mistake leading to the breach of personal details of its entire staff.
Details of the PSNI’s 10,000 staff, including officers and civilian workers, were revealed after a Freedom of Information request was filed. In their response, PSNI published the surnames and initials of staff, the department they work in, and their current role.
The information was published online for about two hours before it was removed.
Assistant Chief Constable Chris Todd, in a television appearance to address the breach, said it was the fault of human error.
The data breach hit every rank in the organisation, up to the Chief Constable.
Even though personal details such as addresses, emails, and phone numbers were not disclosed, there is already a “severe threat” to police staff in Northern Ireland, according to Todd.
“I understand there will be considerable concern to many of my colleagues and their families. At the moment we operate where there’s a severe threat to our colleagues from Northern Ireland related terrorism,” he said in a press conference.
Police officers are often the targets of republican supporters in Northern Ireland – the terrorist threat level in Northern Ireland was raised from substantial to severe in March this year.
Due to sectarian divide still plaguing the nation, many police officers keep their occupation a secret, even from family members.
This breach could reveal the occupations of officers to the public, therefore putting them at direct risk.
Recommended reading
- Reprimand Issued to Police Over Mishandled Data
- Edinburgh and Glasgow See Online Piracy Police Raids
- South Lanarkshire Council Publishes Staff Salaries in Data Leak
The Police Federation of Northern Ireland called for answers and expressed their dismay at the data breach.
“This is a breach of monumental proportions. Even if it was done accidentally, it still represents a data and security breach that should never have happened,” Liam Kelly, chair of the Police Federation of Northern Ireland, said.
“Rigorous safeguards ought to have been in place to protect this valuable information which, if in the wrong hands, could do incalculable damage.
“The men and women I represent are appalled by this breach. They are shocked, dismayed and justifiably angry. Like me, they are demanding action to address this unprecedented disclosure of sensitive information.”
An FOI request revealed that only 37.1% of the PSNI are Catholic, 15% of which were born outside of Northern Ireland.
The Police in Ireland have historically been predominantly Protestant and Unionist, until a 2001 ruling which put in place affirmative action to hire more Catholics. The rule was lifted in 2011, however, and the number of Catholics compared to Protestants is still low.
The last attack from Police officers in Northern Ireland took place in February this year, sparking the rise in terrorist threat level.
If the data breach had more personal information, including addresses or other identifiers, then it could have lead to a “potentially calamitous situation,” according to Kelly, outline the severity of data breaches.
Jude McCorry, CEO of Cyber and Fraud Centre Scotland, commented on the situation: “Data breaches can be caused by many factors, and one of the most common causes is cyber attack. This impacts organisations large and small, as well as affecting individuals. If any organisations
in Scotland need support to mitigate the impacts of an attack, our free Incident Response helpline is available on 0800 167 0623.
“If you are concerned your organisation has been the victim of a cyber attack or data breach, please ensure that you report the incident to Police Scotland on 101. You can also call our free helpline, and our team will provide expert guidance to help you resume operations.
“If you are an individual and think your data may have been stolen in a data breach, you can take some simple steps to mitigate the impact such as being alert to phishing attacks, safeguarding other online accounts and monitoring your bank account for suspicious activity. Further guidance for individuals affected by a data breach can be found here.”
“Organisations concerned about their security, in general, can also get in touch to confirm they have the right processes in place. There is also a wide range of resources available on our website and via CyberScotland, as well as free training that can help your organisation protect itself against future cyber attacks”.





