The Met Police Accidentally Exposed 143 Al Fayed Victims' Email Addresses

The Metropolitan Police has apologised after accidentally revealing the email addresses of 143 victims of Mohamed Al Fayed in a group update about its ongoing investigation into the former Harrods owner (The Guardian, 15 August 2026).
A Met spokesperson confirmed the breach occurred on Tuesday, 11 August 2026. The force said it identified the problem quickly and contacted all affected individuals the same day. It blamed "human error" and referred itself to the Information Commissioner — the UK's independent regulator for data privacy. The Telegraph reported that the group email, meant as a private update to victims on the force's distribution list, copied in the addresses of 143 victims visible to roughly a dozen other recipients. The Times, reporting a day earlier on 14 August, put the total number of people who could see the addresses at more than 150 (The Times, 14 August 2026).
The update itself carried substantive news: three additional suspects — one in their 70s and two in their 80s — had been interviewed under caution, meaning they were formally questioned and warned that their answers could be used in future prosecution. This brought the total number of people interviewed under caution to seven. The Met said it was investigating the breach as a matter of priority and reviewing its processes to prevent a recurrence.
This is not the first operational misstep in the Fayed case. In June 2026, the force sent the handwritten account of survivor Joanna Brittan to another victim in Australia. The same month, three survivors complained to the Independent Office for Police Conduct (IOPC) — the watchdog that investigates serious police failures — about the Met's handling of allegations against Fayed between 2018 and 2024. In May 2026, the IOPC launched an investigation into one serving Met officer and four former officers over their handling of those allegations.
The underlying criminal inquiry is vast. More than 400 allegations of sexual misconduct have been made against Fayed, spanning from 1977 to 2014 and encompassing rape, sexual assault, human trafficking, false imprisonment, drugging, physical violence, and forced abortions. Fayed, an Egyptian businessman who owned Harrods, the Ritz hotel in Paris, and Fulham FC, died in 2023 aged 94 without facing any charges.
The Met's current investigation, designated Operation Cornpoppy, was launched roughly 21 months before the August 2026 breach. It focuses on people who may have facilitated or enabled Fayed's crimes. The force is investigating allegations from at least 155 victims, at least 21 of whom are understood to have come forward before Fayed's death. Separately, lawyers representing the Justice for Fayed and Harrods Survivors group said 421 people had come forward about abuse allegedly taking place at Harrods, the Ritz, Fulham FC, and other premises owned by Fayed.
The victim collective No One Above, founded by survivors of abuse at Fayed's hands, has urged the National Crime Agency — the UK's lead body for tackling serious and organised crime — to establish a joint investigation team with the Met and assume oversight of the inquiry. That call now carries added weight given the repeated data-handling failures.
The broader context here is one of institutional trust under strain. The Met is simultaneously managing a complex, multi-suspect investigation into alleged enabling of serial abuse over decades while grappling with self-inflicted breaches of victim confidentiality. The IOPC's investigation into serving and former officers, the referral to the Information Commissioner, and the collective's push for NCA involvement all point toward a governance question that extends beyond individual operational errors: whether the Met can maintain the confidence of victims necessary to sustain the inquiry, or whether independent oversight will be compelled by the trajectory of events. Each breach narrows the margin for error the force has left.


