Around 300 staff at Scotland’s prosecution service have had their personal work details exposed online in a third party data breach.
The breach occurred after Crown Office & Procurator Fiscal Service staff took part in an online data maturity last year organised by the Scottish Government and managed by an external supplier.
The supplier – who has not been named – became aware of suspicious activity on August 5th and immediately began investigating the incident.
Steps were taken to secure systems, establish how the breach occurred and identify what information may have been accessed.
The information affected is limited to employment-related information connected with the survey, such as names, roles and work email addresses.
A COPFS spokesperson said: “COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey.
“This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service.
“Colleagues have been reminded of guidance on responding to any phishing or scam attempts which may arise from this third-party breach.”
The agency said there is currently “no evidence” that information relating to cases, victims, witnesses or members of the public has been affected.
The supplier’s investigation remains ongoing and further work is underway to establish the full circumstances of the incident.
Former British military intelligence colonel Philip Ingram MBE called on the Scottish Government to reveal the name of the supplier, in the name of transparency and to provide assurance to other customers of the supplier.
He said: “This could be the tip of the iceberg, and the external supplier should be named as they are fulfilling a public contract.”
He added: “In terms of attribution for this type of breach, it is obviously difficult to speculate. One can never discount nation states behind this type of breach, where they pursue government directly or suppliers fulfilling government contracts.
“But given the nature of COPFS, it could be organised crime looking to identify and potentially exploit individuals in the prosecution service by applying pressure for their own gain.”
