An investigation has determined that the premature disclosure of confidential information from Rachel Reeves’s Budget was not due to deliberate leaking but rather a result of IT vulnerabilities. The Office for Budget Responsibility (OBR) described the incident as the most significant failure in its 15-year history and engaged a cyber security expert, Professor Ciaran Martin, to assist in the inquiry after official projections were mistakenly made available on its website nearly an hour before schedule.
Typically, Budget details are kept confidential due to their market sensitivity. The Chancellor only became aware of the breach while in the House of Commons preparing to deliver her speech.
The investigation revealed that the incident was not caused by hostile cyber activities or human error but rather by two technical glitches related to the OBR’s use of the WordPress publishing platform. Surprisingly, a similar premature disclosure had occurred before the Chancellor’s Spring Statement in March, though it was considered benign as no action was taken.
During the period when the document was accessible online, it was viewed 43 times by 32 unique IP addresses. The initial successful access attempt at 11:35 was preceded by 32 unsuccessful attempts, indicating persistence on the part of the user.
Addressing Members of Parliament, Treasury minister James Murray emphasized the severity of the breach, labeling it a fundamental failure of responsibility that should never have occurred. He expressed concern over the pre-existing vulnerabilities and the potential early exposure of the March Spring Statement forecast.
The report highlighted the need for the OBR to overhaul its publication procedures for important documents to rebuild trust. It stressed the urgency of revising the arrangements for releasing key forecasts and conducting a comprehensive review of all publication protocols.
