Following a recent investigation, it was determined that the premature disclosure of sensitive information prior to Rachel Reeves’s Budget was not a deliberate act of leaking but rather a result of IT vulnerabilities. The Office for Budget Responsibility (OBR) labeled the incident as the most significant failure in its 15-year history. The mishap occurred when official forecasts were mistakenly posted on the OBR’s website nearly an hour ahead of schedule.
Typically, Budget details are closely guarded due to their market sensitivity. The Chancellor was unaware of the breach until she was in the Commons chamber preparing to deliver her speech. The investigation revealed that there was no indication of malicious cyber activity by external entities but rather two technical errors related to the OBR’s use of the WordPress publishing platform.
Interestingly, it was discovered that a similar premature disclosure had occurred before the Chancellor’s Spring Statement in March, although no consequential actions were taken as it was deemed non-malicious. The investigation disclosed that the sensitive document was accessible online between 11:30 and 12:08, with 43 accesses by 32 unique IP addresses.
Addressing Parliament, Treasury minister James Murray condemned the incident as a serious violation of confidential information and a breach of the OBR’s obligations. He expressed concerns over the existing vulnerabilities that may have led to the early release of the Spring Statement forecast. Murray highlighted the alarming prospect of market-sensitive information reaching a limited group of individuals prematurely, potentially impacting market behavior.
The OBR acknowledged the severity of the incident in a statement, emphasizing the disruption it caused and issuing apologies for the lapse. The report recommended a thorough review of the OBR’s document publication procedures to restore trust and prevent such occurrences in the future. It called for immediate changes to the publication process of critical documents and a comprehensive assessment of all publication protocols.
