Plymouth City Council disclosed that a mass email sent to home-schooling families exposed the recipients' email addresses to one another. The incident was caused by staff sending the message without using blind carbon copy (BCC), affecting approximately 500 families; the council said no child-specific information was included, asked recipients to delete the message, and reported the breach to the UK Information Commissioner's Office, which closed the case after giving data-protection advice.
Why it matters: Affected families had their contact details disclosed without consent, creating privacy and possible phishing risks even though no more sensitive data was reportedly included. Public bodies should review bulk-email controls and recipients should be cautious about unexpected follow-up messages referencing the incident.
2026.06.12
100% relevant
This article establishes a distinct local-government data exposure incident involving Plymouth City Council, separate from other tracked email disclosure mistakes.
← Back to all stories