Concerns Mount Over GOV.UK One Login Security as UK Digital Wallet Plans Advance

UK's Labour Rules Out Digital ID System for Immigration

New reporting from ITV News says senior UK civil servants working on the government’s GOV.UK One Login programme have raised serious concerns about the system’s security posture. One Login is the identity layer behind the UK’s planned Digital Wallet initiative and is already used by an estimated 13 million people to access services such as state pensions, passport-related services, and professional registrations.

According to ITV, whistleblowers with direct knowledge of the programme believe there are significant weaknesses that could expose large volumes of personal data. The Digital Wallet is expected to hold key identity attributes — including name, date of birth, nationality or residency status, and a biometric facial image. ITV also reports the government has said digital ID will be mandatory for all adults by 2029, though the requirement has not been fully detailed in formal programme documentation.

ITV reports the whistleblowers say One Login is not meeting required UK government cyber standards, including Secure by Design principles and the Cyber Assessment Framework. The report also cites claims that people without the expected level of security clearance were able to access sensitive system components, including development staff based in Romania, and that system administrators used unsecured devices that could create a route from the public internet into protected environments.

Leaked internal material referenced by ITV indicates investigators assessed the programme as high risk. ITV says the National Cyber Security Centre identified potential impacts ranging from large-scale theft of personal data and fraud against government services to economic harm, and the possible exposure of people such as protected witnesses, intelligence personnel, or foreign dissidents.

One described episode involved a red team exercise in which a remote attacker allegedly placed malware on a system administrator device and gained access to sensitive areas without triggering monitoring alerts. The government told ITV this was a deliberately constructed scenario after weeks of unsuccessful attempts, used to evaluate controls, but the whistleblowers expressed concern that the access went undetected.

A UK government spokesperson told ITV that protecting user data is a top priority, that the programme works closely with the NCSC, that staff hold appropriate security clearances, and that vulnerabilities found through testing are addressed.

Sources: ITV News, GOV.UK, UK Parliament Research Briefing

By the Mobile ID World Editorial Team