World

Police Accidentally Shared Email Addresses of 143 Al Fayed Abuse Victims

Elena MarquezPublished 2month ago5 min readBased on 3 sources
Reading level
Police Accidentally Shared Email Addresses of 143 Al Fayed Abuse Victims
Photo by Abi Skipp / CC BY 2.0

The Metropolitan Police has apologised after accidentally revealing the email addresses of 143 victims of Mohamed Al Fayed in a group update about its investigation into the former Harrods owner (The Guardian, 15 August 2026).

The breach happened on Tuesday, 11 August 2026. The Met said it spotted the mistake quickly and contacted everyone affected that same day. The force blamed "human error" and reported itself to the Information Commissioner, the UK official responsible for protecting people's personal data. The Telegraph reported that the email, meant as a private update for victims, accidentally made 143 victims' addresses visible to about a dozen other people. The Times, reporting a day earlier on 14 August, said more than 150 people could see the addresses (The Times, 14 August 2026).

The email update also carried real news: three more suspects had been questioned by police. One is in their 70s and two are in their 80s. Being "interviewed under caution" means they were formally questioned and told their answers could be used against them if the case goes to court. That brings the total number of people questioned to seven. The Met said it is investigating the breach as a priority and reviewing its processes to stop it happening again.

This is not the first mistake the Met has made in this case. In June 2026, the force sent one survivor's handwritten account to another victim in Australia. That same month, three survivors complained to the Independent Office for Police Conduct (IOPC), the body that investigates serious police mistakes, about how the Met handled allegations against Fayed between 2018 and 2024. In May 2026, the IOPC began investigating one current and four former Met officers over their handling of those allegations.

The criminal investigation behind all of this is enormous. More than 400 people have accused Fayed of sexual misconduct, with allegations spanning from 1977 to 2014. The accusations include rape, sexual assault, human trafficking, false imprisonment, drugging, physical violence, and forced abortions. Fayed, an Egyptian businessman who owned Harrods, the Ritz hotel in Paris, and Fulham FC, died in 2023 at age 94 without ever being charged.

The Met's investigation, called Operation Cornpoppy, started about 21 months before the August 2026 breach. It focuses on people who may have helped or enabled Fayed's crimes. The force is looking into allegations from at least 155 victims. At least 21 of them are believed to have come forward before Fayed died. Separately, lawyers for a group called the Justice for Fayed and Harrods Survivors said 421 people had reported abuse at Harrods, the Ritz, Fulham FC, and other places Fayed owned.

A group founded by survivors, called No One Above, has asked the National Crime Agency, the UK's top body for fighting serious crime, to take over the investigation alongside the Met. That request now carries more weight because of the repeated data mistakes.

The broader context here is about trust. The Met is trying to run a large, complex investigation into decades of alleged abuse while also dealing with its own failures to keep victims' information private. The IOPC investigation, the report to the Information Commissioner, and the survivors' push for outside involvement all raise a bigger question: can the Met keep the confidence of victims long enough to see this through, or will events force independent oversight? Each new mistake leaves the force with less room to recover.