No. The documents you uploaded — passport copies, licences, certificates, CVs — were not taken in this incident.
This is the question we expect you to care about most, so here is the actual reasoning rather than an assurance.
Why we can say this
The files themselves are not held in the databases that were copied. They sit in separate file storage, and the database records only point at them.
The storage did not allow its contents to be listed. A request to enumerate what was in it was refused. That is a verified configuration fact, not an inference — without a list, someone would need the exact address of a specific file, and there was no way to obtain one.
Two things would have yielded those addresses: the table holding uploaded file names, and the message logs where links appear written out in full. Neither was among the records copied. We know exactly which tables were queried during the intrusion, verified across the entire period from 10 to 19 August with no filtering. Eleven tables were taken, and those two are not among them.
What this means for you
Your identity documents themselves — the images, with your photograph and signature — were not obtained in this incident.
That distinction matters. What was taken from the database was text: your passport number, date of birth and nationality. A number is a strong supporting detail for someone attempting fraud in your name. An image of the document is a different order of problem, because it can be used to impersonate the document itself. That did not happen here.
The full list of what was and was not copied is in What was copied in the incident?
A separate issue with the same storage
We would rather tell you this than have you find it elsewhere and wonder what else we left out.
Separately from this incident, an older storage location was found to be configured so that its contents could be reached without authentication. It held documents uploaded in earlier years. It was closed on 21 August.
Access logging was not switched on for that storage, which means we cannot determine whether anything was ever accessed through it. We are not going to tell you that nothing was, because we do not know, and we would rather say so plainly. What we can tell you is that it is closed now, that the current storage was never configured that way, and that this is separate from the intrusion described in your notice.
If you uploaded documents to us before 2024 and want to know what is held for you, ask — see How do I get a copy of my data?
What you should still do
The text details that were taken are enough to make an approach sound convincing, so treat unexpected contact referencing your work with us as suspect, and watch for accounts opened in your name.
Change your Quarterdeck password, because that was among the data copied — see Do I need to change my Quarterdeck password?
The rest of the practical guidance is in What should I do to protect myself?
