Skip to main content

Research

Around 1 in 5 reported data-security incidents is a misdirected email

Why message-level protection matters as much as the connection

Standard email protects the connection between servers, not the message itself. That leaves sensitive content readable wherever it lands, and the most commonly reported failure is simply sending it to the wrong person.

Hands typing on a laptop in a dark office, with green code cascading across the screen

The problem

The gap in ordinary email

Transport encryption such as TLS protects email while it moves between mail servers. It does not protect the message once it arrives, so the content sits readable in every mailbox, forward, and backup it reaches.

An unattended laptop and keyboard on a desk, surrounded by cables

What message-level protection adds

NCSC guidance explains how TLS and MTA-STS protect email connections in transit. Message-level encryption protects the content itself, so it stays unreadable in the wrong mailbox. Recipient authentication then decides who can open it.

A smartphone secured with a chain and padlock

The numbers

What the evidence shows

Three measures of how sensitive email goes wrong, from the ICO, Verizon, and our own consumer research.

Industry icon purple

Around 1 in 5

of data-security incidents reported to the ICO are an email sent to the wrong recipient, the single most commonly reported type (2022-2024).
Finance icon purple

24% of UK adults

have accidentally sent personal data to the wrong recipient, in our 2023 consumer research.
Magnifying glass

The majority of breaches

involve a human element, at 62% in Verizon’s 2026 Data Breach Investigations Report.

What this means

Protect the content, then control access

Misdirected email is a people-and-process failure, not a transport failure, so the response has to hold up after the mistake has been made.

The way forward

Closing the gap

Protect sensitive messages at message level, so the protection stays with the content after delivery. Add a recipient check where the content warrants it. Keep contact data accurate, and use send-time checks to reduce addressing mistakes.

  • Message-level protection, so the protection stays with the content after delivery
  • A recipient check before the content opens, proportionate to what it contains
  • Accurate, governed contact data
  • Send-time prompts to catch addressing mistakes
Hands typing on a laptop

From The Founder

Firms can look secure on paper while everyday email workflows stay exposed

“Boards are now expected to treat communication risk with the same seriousness as financial and conduct risk. If phishing and mis-sent client data are not visible in risk reporting, firms can look secure on paper while everyday email workflows stay exposed.”

Paul Holland Founder and CEO, Beyond Encryption (Mailock)
Paul Holland during a Mailock interview

Questions

Questions about this research

Is my email not already encrypted?

Usually in transit, and that is worth having. Transport encryption such as TLS protects the connection between mail servers. It does not protect the message once it arrives, so the content sits readable in every mailbox, forward, and backup it reaches. In our 2023 consumer research, 45% of UK adults said they understood the term end-to-end encryption and 13% had never heard of it, so this is not a distinction most recipients will make for you.

If a message goes to the wrong person, what does message-level protection actually change?

The content stays unreadable to them. Protection that travels with the message does not depend on the address being right, which matters because a wrong address is the most commonly reported way sensitive email goes wrong. It does not undo the addressing mistake, and you would still handle that as an incident, but the personal data in the message is not exposed by it.

Why is misdirected email the top reported incident type rather than hacking?

Because it is ordinary. A stale contact record, an autocomplete slip, or one wrong character is enough, and it happens inside otherwise well-run processes. Around 1 in 5 data-security incidents reported to the ICO between 2022 and 2024 was an email sent to the wrong recipient, and Verizon's 2026 Data Breach Investigations Report puts a human element in the majority of breaches at 62%.

Is encryption enough on its own?

Not for the messages that matter most. Encryption decides whether the content is readable; a recipient check decides who gets to open it. For a routine document the first may be all you need, and for a financial instruction or an identity-related message it will not be.

Sources and method

Method: Desk research on published UK regulatory and industry sources, plus our own 2023 UK consumer survey. Figures refer to the cited sources and reporting periods rather than every event in the UK.

Sources accessed July 2026.

A team collaborating around a laptop

Mailock encryption

Protect sensitive outbound email

See how Mailock could help your business to keep sensitive email protected after delivery and add a check before the content opens.