A cyber-attack on a contractor linked to the UK Ministry of Defence has exposed the personal data of up to 3,700 people, including Afghans seeking refuge under the Afghan Relocations and Assistance Policy (ARAP). The breach at Inflite The Jet Centre Ltd, which provides ground services for flights linked to the MoD and the Cabinet Office, affected individuals who flew into London Stansted airport between January and March 2024.
In addition to Afghan refugees, the leak may have released information belonging to civil servants, soldiers on routine exercises, and journalists. The company confirmed the incident on its website, stating that “a limited number of company emails” had been accessed. It said the breach had been reported to the Information Commissioner’s Office and that it was working with the National Crime Agency and the National Cyber Security Centre on the investigation.
Inflite said it believed the scope of the incident was limited to email accounts, but as a precaution it had contacted key stakeholders whose data may have been affected during the January-to-March period. A government spokesperson said the incident involved unauthorised access to a small number of emails containing basic personal information, adding: “We take data security extremely seriously and are going above and beyond our legal duties in informing all potentially affected individuals.” The spokesperson stressed that the incident posed no threat to individuals’ safety and did not compromise government systems.
The data is not believed to have been leaked to the dark web or made public. The breach is the latest in a series of data leaks involving Afghan refugee information. In February 2022, a separate breach by a defence official disclosed the personal data of 18,714 Afghans who had worked with British forces. The UK High Court granted a superinjunction in 2023 to suppress information related to that breach, for which the Labour defence secretary, John Healey, later issued an apology.



