Scottish prosecutors' staff data at risk in supplier breach
Scotland's prosecution service warns 300 staff their personal data may be exposed in a cyberattack on a third-party supplier.
Scotland's public prosecution service is grappling with a data breach at an unnamed third-party supplier, warning that the personal information of around 300 staff members may have been compromised. The Crown Office and Procurator Fiscal Service (COPFS) said on Thursday that the supplier detected suspicious activity on its systems on August 5 and launched an investigation. The incident did not affect COPFS's own systems, but the data involved was provided for an online data maturity assessment completed by the prosecution service last year.
Unnamed supplier in the spotlight
COPFS said the Scottish government organized the assessment, and the affected supplier managed it. The potentially exposed information is limited to employment-related data submitted for the exercise, including staff names, roles, and work email addresses. The supplier's identity has not been disclosed, and it remains unclear how the intrusion occurred or what specific data may have been accessed.
In a statement to The Register, a COPFS spokesperson said: "COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey."
"This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service."
— COPFS spokesperson
The spokesperson added that staff have been reminded of guidance on responding to any phishing or scam attempts that may arise from the breach.
Investigation ongoing, questions remain
According to COPFS, the supplier has taken steps to secure its systems and is still investigating how the intrusion happened and precisely what information may have been accessed. COPFS said it would provide further updates if "significant new information" emerges.
The breach leaves many questions unanswered, including who gained access and what they took. The supplier has not been named publicly, and the full scope of the incident has yet to be determined.
Potential link to Metabase zero-day?
It is unclear whether the incident is connected to the recent exploitation of a zero-day vulnerability in business intelligence platform Metabase. The Scottish government did not answer questions about whether the affected supplier used the software. Metabase disclosed this month that attackers had exploited a previously unknown vulnerability in its cloud service, potentially allowing them to gain administrator access and reach connected databases. Modular laptop maker Framework was among those affected, as reported earlier this week.
Context: Scotland's cyber incident streak
The breach at the supplier is the latest in a series of cyber incidents affecting Scottish organizations. In a related development, Scotland's university procurement center confirmed that cybercrooks broke in, and a Scottish NHS trust probes access to medical records of a 9-year-old girl after a man was arrested on suspicion of murder. These incidents highlight the ongoing cybersecurity challenges faced by public bodies in Scotland.
Why it matters for affected staff and beyond
For the 300 COPFS staff members whose data may be exposed, the breach raises the risk of targeted phishing or social engineering attempts using their work email addresses. The reminder from COPFS to be vigilant is a practical step, but the incident underscores the broader vulnerability of supply chains: even if an organization's own defenses hold, a breach at a trusted partner can still put sensitive data at risk. As the investigation continues, the lack of details about the attack method and the identity of the intruders means affected employees should remain cautious about unsolicited communications.
Sources
- The Register Original source
Continue Reading
Security Roundup: Pentagon AI Deal Draws Fire
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.
AmnesiaStealer: New macOS Malware Shows Depth
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
SecurityNewOracle offers free database security tool
Oracle's new Database Security Central tool is free until February 2027, arriving amid rising database attacks.