Front Page News (2385) Healthcare (1961) Conspiracy (1519) Control (1504) Coronavirus (1136) Spirituality (1124) Inspiration (889) ETs UFOs (793) Forbidden History (750) Satanist Pedophiles (705) False Flags (585) Mysteries (566) NWO (517) Cancer (377) Finance (286) Censorship (261) Depopulation (260) Science (236) Cosmos (234) Big Brother (227) Global Warming Hoax (222) Tyranny (209) Mind Control (206) Police State (206) Documentaries (193) MSM (181) Hemp (159) Satanism (143) Bill Gates (134) Education (132) Propaganda (130) 5G Dangers (128) The Matrix (126) Great Reset (126) War (125) The Anunnaki (122) Migrant Crisis (111) Geoengineering (104) George Soros (102) Big Tech (98) Rothschild (97) Big Pharma (96) Chemtrails (95) Pyramids (94) Illuminati (89) Transgender Agenda (87) Occult Knowledge (84) Clinton (83) Voting is Rigged (81) GMO (76) Monsanto (75) Fukushima (69) Free Energy (68) Nuclear Hazard (64) WTC (9/11) (64) Religion (64) The Vatican (62) Reincarnation (61) Cold War 2 (59) Secret Societies (56) Wi-Fi Dangers (54) Child Trafficking (51) Wisdom (50) Inspirational Public Figures (49) Microchip Implant (49) Agenda 2030 (47) Project MKUltra (42) Rockefeller (40) Deep State (40) Consciousness (40) Fluoride (40) Preppers (40) Sexualizing children (39) Empaths (39) Medical Kidnapping (39) War on Children (34) World Economic Forum (33) Planned Parenthood (33) Art. in German (32) Nikola Tesla (30) Free Speech (30) Julie Alexander (30) FEMA (29) Jeffrey Epstein (29) Dejan Davchevski (29) Drag Queen Story Time (27) Meditation (26) Bilderberg (26) Transhumanism (26) W.H.O. (24) HAARP (24) SJW (24) Caeli Francisco (23) PhD Anonymous (23) Secret Space Program (22) Hollow Earth (22) Freemasonry (21) War on Drugs (20) Pineal Gland (19) Fake News (18) JFK (18) Julian Websdale (17) OOPArt (17) Feminism (16) Pienaar Arno (16) Quotes (15) Alzheimer's (15) Archons (15) Internet of Things (14) Zika Virus (14) Contact Tracing (14) Pole Shift (14) War on Food (14) Green New Deal (13) Pornification & Sexualization (13) Racism (13) Ayahuasca (13) Crop Circles (13) Mark Nestmann (12) Digital ID (12) Zionism (12) Zodiac (12) Time Travel (12) Crisis Actors (12) War on Cash (11) Rene’ Descartes (11) Technocracy (11) Synchronicity (10) Fasting (10) Federal Reserve (9) TROLLS (9) Detox (9) Free Spirit (8) Communism (8) Mass Formation Psychosis (8) Sacred Water (8) Henry Kissinger (7) Immunity Passports (7) ID2020 (7) Political Correctness (7) Disney (7) Grounding (7) Diabetes (7) Khali Carol (7) Planet X (7) Demonic Possession (6) Brainwashing (6) Mandela Effect (6) Cashless Agenda (6) Pollution (6) Sustainable Housing (6) Michael Martin (6) Ebola (5) Artificial Intelligence (A.I.) (5) The Bush Family (5) Directed Energy Weapons (4) Great Awakening (3) Giants (3) Zephyr Prayers (3) Black Knight (3) Stephanie MacDonald (3) Makia Freeman (3) Symbolism (3) Strange Murders (3) Laura Jane (3) Universal Basic Income (2) Smart Meters (2) Brexit (2) Crypto News (2) Social Credit Score (2) Mari A. Raphael (2) EMP Dangers (2) Weather Terrorism (2) Orwellian Wrongthink (2) Richard Hoyle (2) DuPont (2) Evil Corporations (2) Sun-gazing (2) Lucy Alvet (2) Cyberattacks (1) Cyber Polygon (1) Papal Bloodlines (1) 17 (1) 12 (1) 227 (1) Smart Dust (1) 244 (1) Sacred Geometry (1) Crystal Skulls (1) Lisa Morris (1)
Home Big Tech

When a Government Website Leaks Your Data: FOI the Breach Response Itself

By · September 12, 2026 · 5 min read · 919 words

Government data breaches now make the news weekly, and the public statements that follow them follow a script: sophisticated attack, contained quickly, no evidence of misuse. The records behind those sentences are often obtainable. The right request is not for the breach, it is for the response to the breach.

When a public body suffers a data breach, a paper trail begins almost immediately: incident reports, notifications to regulators, risk assessments, decisions on whether to tell affected people. Most of that trail is subject to freedom of information law even when the breach itself is being investigated, and requesting it changes the conversation from trusting a press release to reading the timeline. Here is how to do it properly.

Why request the response and not the breach

Asking a body for “all information about the breach” invites refusal. The incident itself is likely to be covered by exemptions: law enforcement investigations, national security, commercial interests of security contractors, personal data of staff or victims. A request framed around the response machinery is different, because the machinery is administrative record-keeping. Timelines, decision logs, notification assessments and post-incident reviews are the kinds of documents agencies create for their own governance, and governance documents are what FOI law was written to release.

A second reason is that the response is where accountability actually lives. Whether passwords were reset, how long notification took, who decided affected individuals did not need to be told, and what was changed afterwards are all questions about decisions, and decisions leave records. The breach is the attacker’s story. The response is the agency’s.

What to ask for, specifically

Vague requests get vague answers and long delays. Concrete categories get concrete documents:

The incident timeline: dates and times of detection, escalation, containment, and classification, with the log or report that records them.

Regulator notifications: the notification sent to the information commissioner or data protection authority, including the date it was filed and the basis for the severity assessment.

The notification decision: any assessment, memo or risk analysis on whether and how to inform affected individuals, including the reasoning if the decision was not to inform.

External assistance: contracts, engagement letters or task orders for forensic or legal firms involved in the response, with dates and scopes. Costs may be separately requestable.

The post-incident review: any lessons-learned report, board briefing, or remediation plan produced after containment.

Correspondence with suppliers: where a third-party processor was involved, the breach notices exchanged under the contract.

Framing matters as much as content. Ask for recorded information, not explanations: FOI law releases documents, not answers to open-ended questions like “why did this take so long”. Request “copies of the notifications and the date each was sent”, not “an explanation of your response”.

The exemptions to expect, and how to narrow around them

Four exemptions do most of the work in these refusals. Law enforcement, where an investigation is live, protects material that could prejudice it. You cannot argue an investigation away, but you can argue that a timeline of dates already disclosed to a regulator is not prejudicial. Personal information protects named individuals; offer to accept redacted copies, which the authority must provide unless the redaction renders the document meaningless. Commercial interests of security contractors protects things like pricing and vulnerability details; the fact that a firm was engaged and when is rarely commercially sensitive. And prejudice to the conduct of public affairs is the catch-all, which the tribunal case law narrows: there must be a real and specific likelihood of harm, not a general nervousness.

The pattern that works is segmentation. Accept that the investigation file stays closed for now, and get the surrounding documentation: the regulator notification, the notification decision, the review. Six months later, re-request the investigation material; many authorities will release more once a case is closed, and a second request that follows a first is harder to fob off with boilerplate.

Practical sequence

File quickly. Internal review reports are drafted while memory is fresh, but more importantly, some bodies have document-deletion or archiving practices that shorten the life of incident material. A request filed within weeks of the breach covers documents that a request filed two years later may not.

Ask for the information handling log as well as the documents: every FOI authority keeps a record of how it processed your request, and if the handling goes wrong, that log is itself requestable evidence.

Use the internal review step when refusal letters are template language. A large share of first refusals on breach-response requests are partially overturned on review, because the review officer actually reads the documents against the exemption claimed. Beyond that, the information commissioner’s office takes complaints, and the complainant does not need a lawyer to file.

One structural note: several high-profile breach response documents in recent years were released not because an authority chose transparency but because a requester kept the file open through review and re-request. Persistence is not a tactic of last resort here, it is the tactic.

The boundary of what you will get

Be realistic about the ceiling. You are unlikely to obtain attacker details, exploit specifics, or unredacted personal data of victims, and you should not want the latter. What you can realistically obtain is the clock: when the body knew, who it told, how long affected people waited, and what changed afterwards. That clock, read against the press release, is the whole story. Where the gap is wide, the documents make the point without a word of commentary from you.

Big Tech

Stay in the know

Get the latest investigations delivered to your inbox. No spam, ever.