In a café a stone’s throw from the Houses of Parliament, Alex* stirs his coffee and begins to tell me his story. He is a Grade 6 civil servant turned whistleblower who had been working on a project with the ticket name “Digital Identity”.
With digital identity systems, when things go wrong, they go very wrong, he says. “It makes losing CDs of the child benefit database look trivial,” he explains in this, his first print interview.
“If Digital Identity is hacked, and it certainly can be, it will be the worst data breach in UK government history. Once the data is stolen, it can be used for mass identity theft and then the system could be shut down by ransomware to exclude genuine users from accessing any of the connected government services.”
Alex knew this was no hypothetical fear. The digital identity system, known to the outside world as One Login, could be hacked without detection. Security researchers contracted by the civil service to probe the system found they could take control of it with ease. They could then take command of the code, allowing them to plant malware and cover their tracks.
Worryingly, many of the staff and contractors did not have the required security clearance. Large parts of the project had been outsourced, and, incredibly, some of these parts were being developed in Romania for the contractor Deloitte. Romania is one of the world’s cybercrime hotspots, home to the city of Râmnicu Vâlcea (aka “Hackerville”), and its cybercriminals are widely regarded as amongst the most dangerous in the world.
Hostile agents from Russia are active in the country which, it has subsequently transpired, escaped the notice of senior management in Government Digital Service (GDS) — the department for Science, Innovation and Technology unit entrusted with Digital Identity.
Alex has amassed years of experience assessing risk on IT projects, a specialist skill known as “information assurance”. In the Horizon scandal, innocent subpostmasters employed by the Post Office were framed for crimes they did not commit. A forensic trail exposed both what happened to them and the subsequent cover-up. What was the risk of this happening on a British government project? It was Alex’s job to find out.
When Alex raised concerns internally, his team was sidelined. Management closed ranks instead. The revelations about this I subsequently made in the Telegraph prompted questions in Parliament. Dame Pauline Neville-Jones, who had announced the scrapping of Tony Blair’s digital ID cards in 2010, called One Login a flawed piece of critical national infrastructure.
Since being unveiled by Michael Gove in 2021, One Login has cost over £300 million, with more than 700 civil servants and contractors assigned to it. David Davis MP subsequently told a Westminster Hall debate: “It’s worse than Horizon, it’s quite possible malware is already inside it.” Then last September, Sir Keir Starmer announced that a mandatory national digital identity programme, a digital “Britcard”, would be created — and built on the very system that Alex had warned about.
Britcard, a smartphone-based app holding personal credentials and biometric information, will be required to legally start work and obtain accommodation. The King’s Speech in May confirmed that the project was going full steam ahead: 22 million of us are on One Login.
Campaigners are not convinced by reports of the project being cancelled by the new PM, Andy Burnham. “Digital ID continues to be built by the permanent government in Whitehall,” says Phil Booth, founder of No21D and Med Confidential. A tender worth £330m was issued on 30 June to extend One Login. This has not been cancelled. So what makes people so anxious about digital ID? The absence of a requirement to produce proof of one’s identity to the authorities is a distinguishing feature of British civic life. For many people, the spectre of “Papers, please” is the very epitome of state overreach, and opposition to it runs deep and wide.
We have never had identity cards, except for a brief interlude when they were introduced as a wartime measure in 1939. Eleven years later, Clarence Henry “Harry” Willcock, a dry-cleaning manager described by Time magazine as “a peppery Yorkshireman” and a member of Barnet Liberal Association, refused to produce his identity card when challenged by a policeman after being stopped for speeding in Finchley. Churchill’s Conservatives repealed the law in 1952.
Tony Blair’s plastic digital ID cards were originally proposed in the name of public safety after the 9/11 terrorist attacks. Today he espouses digital ID on the grounds of efficiency — a rationalist, utilitarian ambition. “There are permanent secretaries who have never given up the dream of being able to link up databases,” says Booth. “A single digital identifier allows them to do that.”
The case for the state as an identity provider is less justifiable than ever. One positive aspect of the Blair ID cards fiasco was the development of a thriving private sector for digital identities, with companies such as Yoti now regulated under the 2025 Data Act. For age checks in bars and to fulfil financial reporting requirements, for example, the state does not need to offer a product in the marketplace. But having promised it wouldn’t offer a direct competitor, it turned One Login into one, announcing the GOV.UK wallet. Britcard is merely a rebrand.
Trouble brewed when Alex submitted his initial risk report for One Login. It documented how the Government Digital Service did not know exactly who was accessing the system and could not lock down the hundreds of computers used by staff and contractors used to build it.
“My team and I wrote a series of briefings. They were ignored. Vacant roles were not filled,” he recalls. Then the management decided that Alex’s team was the real problem.
Frustrated, Alex went over the heads of GDS to appeal to the Cabinet Office — which wasn’t interested either. With these avenues exhausted, he invoked the 1998 Public Interest Disclosure Act, which affords whistleblowers some protection, providing his own legal representation. The Whitehall response was robust: “They told me to remove critical statements from the briefings on Digital Identity and to halve the size of my Information Assurance team,” he says. “Then I was told if we issued any more ‘uncollaborative’ briefings we would be replaced with a third-party service.”
“The overt hostility towards cyber-security professionals then became a pile-on from managers,” he adds. “Management simply ignored everything my team said, including warnings that GDS was failing to meet minimum cyber security standards.”
Without much hope, Alex submitted a Subject Access Request to discover what the management were saying about him and his team. What they revealed were private internal communications consistent with a culture of management intimidation, and an indifference to cybersecurity risks. The files also confirmed that management knew that the One Login system, which had now gone live, was processing personal data at “high residual risk”. The risk was kept from the rest of Whitehall. Once ministers were notified of Alex’s concerns, the bullying only intensified.
“Three days after the minister met the Digital Identity leadership team I was fast-tracked into a disciplinary process,” Alex recalls. “Over the following year I slowly realised all the slogans about zero tolerance for bullying, providing a safe space for staff to raise concerns, and the Civil Service Code core values for integrity, honesty and objectivity, were just a charade,” he says.
Alex looks weary as he reflects on the penetration test that confirmed One Login could be breached without detection. Last year, a team of external so-called Red Team “hackers” simulating a hostile cyber attack easily gained access to the system by taking advantage of unsecured Government laptops. If the warnings he’d given four years ago had been heeded, that should not have happened.
In the United States, President Trump has ordered all federal digital ID work to be frozen because it posed a risk to the security of US citizens. It’s an irresistible target for a state sponsored hacker. Why then did the Cabinet Office remove the team responsible for assessing the security of One Login, the digital identity project, and suppress the news?
With millions of us being forcibly enrolled onto what will become Britcard, we may find out in the worst possible way.
*Alex has now left the civil service. Some personal details have been changed.
(UKR)
