VYPR
breachPublished Aug 14, 2026· 1 source

Scottish Prosecutors Expose Staff Data in Third-Party Supplier Breach

Scotland's Crown Office and Procurator Fiscal Service (COPFS) reported a data breach affecting approximately 300 staff members, originating from an unnamed third-party supplier.

Scotland's Crown Office and Procurator Fiscal Service (COPFS) has disclosed a data breach that potentially exposed the personal information of around 300 staff members. The incident did not occur within COPFS's own systems but rather at an unnamed third-party supplier responsible for managing a data maturity assessment.

The breach was detected by the supplier on August 5, prompting an immediate investigation. COPFS confirmed that its internal systems remained secure and unaffected. The compromised data is believed to be limited to employment-related details submitted by staff for an online data maturity assessment conducted last year on behalf of the Scottish government.

Potentially exposed information includes staff names, their job roles, and work email addresses. COPFS has emphasized that the incident is unrelated to any ongoing casework and does not involve sensitive or confidential case information. The operational work of the prosecution service has not been impacted.

In response to the breach, COPFS has reminded its employees about existing guidance on handling potential phishing or scam attempts that might arise from the compromised data. The supplier has reportedly taken steps to secure its systems and is continuing to investigate the root cause and exact scope of the intrusion.

While the supplier is working to uncover more details, the identity of the attacker and the full extent of the data accessed remain unclear. The incident raises questions about the security practices of third-party vendors handling sensitive government data.

It is currently unknown if this breach is connected to the recent exploitation of a zero-day vulnerability in the Metabase business intelligence platform, which was disclosed earlier this month. Metabase had warned that attackers could gain administrator access and reach connected databases through this flaw.

COPFS has stated that it will provide further updates should any significant new information come to light regarding the breach. The incident underscores the persistent risks associated with supply chain vulnerabilities and the importance of robust third-party risk management.

The focus remains on the supplier's ongoing investigation to determine the full impact and to implement necessary security enhancements to prevent future occurrences.

Synthesized by Vypr AI