City of York Council Data Breach Exposes Disabled Residents' Email Addresses

City of York Council Data Breach Exposes Disabled Residents' Email Addresses

First seen 5 Jun 2026, 10:38 UTC Theregisterwww.yorkpress.co.uk 90% similarity 51.1

Article Content

Browse articles
ThreatCluster

A data breach at City of York Council revealed the email addresses of hundreds of Blue Badge holders. The breach occurred when emails were sent without using the blind carbon copy (BCC) function, allowing recipients to see each other's email addresses. This incident has raised concerns among affected individuals, as it disclosed their status as disabled residents. The council has initiated an investigation and is assessing the potential impact on those affected. Affected residents have been advised to delete the emails and remain vigilant for suspicious messages. The council is also evaluating whether the breach requires notification to the Information Commissioner's Office within the statutory timeframe. The investigation is ongoing, and the council has committed to improving its data protection measures.

Key Points: • City of York Council mistakenly exposed email addresses of hundreds of Blue Badge holders. • The breach occurred due to emails sent without using the BCC function. • Affected individuals have been advised to delete emails and stay alert for suspicious messages.

ThreatCluster AI

Timeline

2026-05-28
Emails sent revealing Blue Badge holders' email addresses
City of York Council sent multiple emails without BCC, exposing recipients' email addresses to each other.
York Press
2026-05-28
Fourth email sent acknowledging the error
The council sent a follow-up email asking recipients to delete previous emails and remain vigilant for suspicious messages.
The Register
2026-06-05
Investigation launched by City of York Council
The council confirmed it is investigating the data breach and assessing its impact on affected individuals.
York Press

Community

Browse all →

Tracked Entities in This Story