EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/uk-mod-payroll-breach-2024
096/430

File EL-0335CriticalResolvedData Breach / Third-Party Vendor Breach / Supply Chain Attack

UK Ministry of Defence Payroll Data Breach

Also filed as MOD Payroll System Hack · British Military Personnel Data Leak

The UK Ministry of Defence suffered a catastrophic data breach in May 2024 when a third-party payroll system was compromised, exposing the personal information of all 272,000 current and former British armed forces personnel including names, addresses, bank account details, and passport numbers.

  • #government
  • #military
  • #national-security
  • #supply-chain
  • #payroll-data
  • #pii
  • #uk-mod
Notoriety10/10
Event
6 May 2024
Disclosed
8 May 2024
Target
UK Ministry of Defence
Scale
272K people
Status
Resolved

01Summary

In May 2024, the UK Ministry of Defence confirmed that a third-party contractor managing the armed forces payroll system had suffered a cyber intrusion, resulting in the exposure of personal data for all 272,000 current and former members of the British Armed Forces. The compromised database contained names, addresses, dates of birth, bank account numbers, passport numbers, National Insurance numbers, and service records across the Royal Navy, British Army, and Royal Air Force. The breach was particularly severe because the aggregated dataset provided a comprehensive targeting profile for hostile intelligence services.

02Background

The UK Ministry of Defence operates one of the world's most capable military forces. The compromised payroll system was operated by a third-party contractor as part of MOD's outsourced shared services arrangement.

03Key revelations

  1. 01Every current and former UK armed forces member had personal data stolen
  2. 02Bank account details and passport numbers of active military personnel exposed
  3. 03Supply chain vulnerability in government outsourced services exposed
  4. 04National security implications for deployed personnel and their families

04Technical analysis

The attack targeted the third-party contractor's network, exploiting vulnerabilities in their payroll application to gain database-level access to the MOD personnel database. The full database was extracted, indicating sophisticated access.

Attack vector
Third-party contractor network compromise with database-level access
Attack method
Supply chain attack targeting outsourced government payroll services
Initial access
Third-party contractor network vulnerability exploitation
Exfiltration
Full database extraction via compromised contractor systems

05Threat actor

Unknown threat actors, suspected to be state-sponsored intelligence operation given the comprehensive targeting value of the stolen data.

Attribution sources

  • BleepingComputer
  • Media reports

06Victims and impact

Countries affected

  • United Kingdom

07Data exposed

Data types

  • Full names
  • Home addresses
  • Dates of birth
  • Bank account numbers
  • Passport numbers
  • National Insurance numbers
  • Service records
  • Military IDs

08Financial damage

Unquantifiable national security damage. Significant costs for personnel protection measures and identity monitoring.

09Timeline

  1. 2024-05-06MOD confirms payroll data breach affecting all armed forces personnel
  2. 2024-05-07NCSC launches investigation
  3. 2024-05-10Emergency parliamentary statement by Defence Secretary
  4. 2024-06-01Comprehensive MOD contractor security review ordered

10Reaction and fallout

Public reaction

Outrage across the UK over the exposure of military personnel to potential targeting. Families of deployed service members expressed particular concern about home addresses being in hostile hands.

Political impact

Emergency parliamentary session on national security data protection. Defence Secretary faced intense scrutiny. Review of all MOD third-party contractor security arrangements ordered.

11Legal

NCSC investigation. Potential legal action against contractor. Data protection regulator investigation under UK GDPR and DPA 2018.

Civil lawsuits

  • Potential class-action from affected service personnel

12Aftermath

Policy changes

  • Complete review of MOD contractor security requirements
  • Enhanced vetting of third-party vendors handling sensitive military data

Security improvements

  • New government supply chain security standards
  • Enhanced monitoring of contractor network access
  • Reduced data sharing with third-party vendors

13Significance and legacy

Significance

One of the most serious national security data breaches in UK history, compromising personal data of every British service member and exposing them to potential targeting.

Legacy

Fundamentally changed how the UK government approaches supply chain cybersecurity for military data.

14Disclosure and media

Authentication
Breach notification and media coverage

Publishing organisations

  • BleepingComputer

15Field notes

  1. 01The breach affected active special forces personnel whose identities and home addresses were among the exposed data
  2. 02The compromised contractor had held the MOD payroll contract for over a decade

16Resolution

Investigation led by NCSC and MOD Police ongoing. Affected personnel notified and offered identity protection services.

17Sources

References

  1. [1]BBC News: MOD payroll data breach
  2. [2]The Guardian: UK armed forces data leak
  3. [3]NCSC investigation announcement
Fact sheetEL-0335

Dates

Event
6 May 2024
Started
6 May 2024
Duration
41 days
Discovered
6 May 2024
Disclosed
8 May 2024
Ongoing
No

Target

Organisation
United Kingdom Ministry of Defence
Type
Government Agency
Sector
Defense / Military
Country
United Kingdom
Gov. level
National

Actor

Motivation
Espionage and intelligence gathering against UK military personnel. Comprehensive dataset provides targeting database for hostile intelligence services.
Attribution
Low
Arrested
No
Convicted
No

Data

People
272,000
Records
272,000
Sensitivity
Critical
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.