COPFS staff data breach affects about 300 after supplier incident
About 300 Scottish prosecution-service employees may have had survey data exposed, while COPFS says casework and its systems were unaffected.
By Renata Fuchs · Policy Reporter
· 3 min read
The COPFS staff data breach may have affected employment-related information belonging to about 300 employees after suspicious activity was detected at an unnamed supplier on 5 August. The Crown Office and Procurator Fiscal Service says its own systems were not compromised, and that the incident did not involve casework or disrupt the prosecution service.
The affected staff had taken part in an online public-sector data-maturity assessment during the previous year. The Scottish Government organised the exercise, while the unnamed external supplier managed it, according to COPFS statements reported by The Register.
COPFS says the potentially affected information is limited to employment-related survey data, including names, job roles and work email addresses. The service said there was no evidence at the time of reporting that information concerning cases, victims, witnesses or members of the public had been affected.
What information may have been exposed in the COPFS staff data breach?
What was accessed has not been established. COPFS has described the possible exposure as survey-related work information, while the Daily Record reported that files may also have contained employees’ places of work. That latter detail was reported by the outlet and was not included in the COPFS statement reproduced in its report.
The supplier has secured its systems and is investigating how the intrusion occurred and which information, if any, was accessed. Its identity has not been disclosed. COPFS said it would provide further updates if significant new information emerged.
Employees were reminded of guidance covering phishing and scam attempts that may arise from the third-party breach. The FDA union, which represents public-sector staff, said it would seek confirmation that affected workers had received clear information about the data involved, associated risks and available support, the Daily Record reported.
What is known about the supplier investigation?
The available reporting does not identify the intrusion method, confirm the full data set accessed or name the supplier. The Scottish Government said ministers had been informed and were receiving updates. Reporting also raised the possibility of a link to a recently disclosed Metabase cloud-service vulnerability, but no connection has been confirmed and the Scottish Government did not answer a question about whether the supplier used the software.
The episode concerns a third party rather than COPFS’s prosecution technology estate, based on the service’s account. COPFS is Scotland’s public prosecution and death-investigation authority. For organisations that share data with outside providers, enterprise security is generally a programme spanning technical controls, policies, trained users and incident response; the current reporting does not establish which controls or processes the supplier had in place.
UK data-protection rules can require organisations to notify the Information Commissioner’s Office within 72 hours of learning of a personal-data breach where it risks people’s rights and freedoms. The reporting does not establish whether a notification was made in this case.
This story draws on original reporting from The Register.