Decoding the world of cybersecurity

Supplier breach reaches Scottish prosecutors

Scotland’s prosecution service says employee information was exposed through an external supplier, while its own systems, casework, victims, and witnesses remain unaffected.

Supplier breach reaches Scottish prosecutors
Summary
  • COPFS says a third-party supplier suffered a security incident linked to an online data maturity assessment.
  • Exposed information is limited to employment-related data including names, roles, and work email addresses.
  • The service says its own systems and information relating to criminal cases, victims, witnesses, and the public were not affected.

Scotland’s public prosecution service has disclosed a third-party data breach involving employee information collected through an external assessment, while stressing that its own systems and confidential casework were not compromised.

The Crown Office and Procurator Fiscal Service said the incident involved a supplier that managed an online data maturity assessment organised by the Scottish Government. COPFS participated in the exercise last year.

The affected information is limited to employment-related material connected with the survey, including names, job roles, and work email addresses. COPFS said there is currently no evidence that information relating to criminal cases, victims, witnesses, or other members of the public has been affected.

The supplier became aware of suspicious activity on 5 August and began an investigation, taking steps to secure systems and determine how the breach occurred and what information may have been accessed. That work remains in progress.

COPFS’s own operational environment was not breached, yet information belonging to its workforce was still exposed because it had been provided to an external organisation for a legitimate business purpose. Public-sector information increasingly sits across assessment providers, HR platforms, collaboration systems, consultants, survey tools, and other supporting services that do not need access to core operational networks to hold useful data.

Names, job titles, and work email addresses carry less intrinsic sensitivity than case files but can still acquire value through context. A verified list connecting individuals with roles inside a prosecution authority can support impersonation or targeted phishing aimed at identifying staff with access to more sensitive functions. COPFS has not reported evidence that such activity has occurred.

The external assessment itself also created a dataset that did not previously exist in the same form. Exercises intended to measure organisational maturity can collect information about employees, responsibilities, processes, organisational structure, and internal capability, placing retention, access, and deletion controls around the assessment provider within the wider information-governance environment.

Public bodies remain responsible for knowing where their information is held even when they do not operate the systems involved. Contracts and supplier assessments form part of that process, but incident response also depends on being able to establish quickly which data an external provider holds and whether an exposure reaches operational or regulated information.

COPFS’s public notice draws clear boundaries around the affected material. There is no evidence of impact to confidential casework or the operational work of the prosecution service, and no current evidence involving cases, victims, witnesses, or members of the public.

Those boundaries should remain intact unless the supplier investigation produces different evidence. An incident affecting data connected with a justice organisation is not the same as compromise of justice systems themselves.

The confirmed exposure is narrower: employment information supplied for a routine external assessment became part of a supplier security incident. The case adds another example of public-sector exposure being shaped by contractors and specialist services that sit beyond the government’s own networks while still holding government information.

×