Skip to content
26158504.city York Council Investigation Blue Badge Data Breach

26158504.city York Council Investigation Blue Badge Data Breach

www.yorkpress.co.uk June 5, 2026

AN investigation has been launched after a list of blue badge holders was mistakenly emailed out by City of York Council.

City of York Council have launched a full investigation after a data breach that took place last week – revealing the personal email addresses of hundreds of disabled people who live in the city.

A member of the public, who did not want to be named, contacted The Press after receiving a string of emails from the council last Thursday (May 28) that showed the email addresses of people who received blue badge updates.

She said three emails were sent out containing updates, followed by a fourth which explained the information was sent without using the blind carbon copy (BCC) function – which meant all of the recipient’s email addresses were visible.

The fourth email also asked that recipients deleted all emails from their inbox, including their deleted items box, and warned them to remain vigilant for any ‘unexpected and suspicious’ messages after the breach.

The York resident, whose email address was shared, said that – due to the nature of her disability – most people in her life were unaware that she had a blue badge and that the breach made her feel upset that this information had now been shared.

She said: “Honestly, I think it’s just disgusting – we’ve been given the details of hundreds of disabled people, which feels unsafe. I’ve got a blue badge, but I don’t like to tell people and I didn’t want everyone to know this.

“I think the council should be taken to task on this. We need more than just a written apology – it’s appalling and I just find it really shocking that it’s even happened.”

A spokesperson at City of York Council, said that an investigation into the error was ongoing and that the council would ‘continue to be as open as possible while ensuring the accuracy of the information we provide’.

They said: “We can confirm that we’re currently investigating a personal data breach. We’re sorry for the concern this has caused, and we want to reassure everyone involved that we’re treating this with the utmost seriousness and urgency.

“As soon as the issue was identified we took immediate steps to contain the situation and activated our established data breach management procedures.

“We’re working carefully to establish exactly what’s happened, alongside conducting a thorough risk assessment - using Information Commissioners Office guidance - to understand any potential impact on individuals.

“In line with our legal obligations, we’re assessing whether the incident meets the threshold for notification to the Information Commissioners Office within the statutory 72-hour timeframe.

“Where there’s any risk to individuals, we’ll ensure that appropriate notifications are made, and that those affected are informed as quickly as possible, with clear advice and support.

“We have already put measures in place to reduce any potential risk and are reviewing our systems and processes to prevent this from happening again.

“Protecting personal information is a responsibility we take extremely seriously, and we are committed to learning from this incident and strengthening our safeguards.”

Extracted Entities

Attack Types (1)

Companies (1)