Decoding the world of cybersecurity

UKGI file exposed officials’ work details

A UK Government Investments file containing management information and the work details of 51 officials remained publicly accessible for around 40 hours after a policy failure.

UKGI file exposed officials’ work details
Summary
  • An internal UKGI file was publicly accessible for around 40 hours and contained high-level management information.
  • The file included the names and work email addresses of 51 government officials.
  • UKGI attributed the exposure to a failure to follow policy and commissioned an external review of its controls and incident preparedness.

A UK Government Investments file containing high-level management information and the names and work email addresses of 51 government officials remained publicly accessible for around 40 hours after a staff member failed to follow established security policies.

UK Government Investments disclosed the breach in its annual report for 2025–26. The organisation said the file contained the names and work email addresses of the officials alongside management information that it did not describe in further detail.

UKGI voluntarily reported the incident to the Information Commissioner’s Office even though it concluded that the breach did not meet the threshold for mandatory notification. The organisation’s Audit and Risk Committee was also informed.

An external company was commissioned to review the incident. According to UKGI, the review found that its response was appropriate and made recommendations to improve controls and incident preparedness. The organisation said the overwhelming majority had either been implemented or would be introduced in the coming months.

The annual report does not identify when the exposure occurred, how the file became public, which platform hosted it, or whether there is evidence that an unauthorised party accessed or downloaded it. Public accessibility establishes a loss of control, but it does not by itself confirm malicious use.

The report confirms that UKGI lost control of the file, but does not establish whether anyone outside its intended audience accessed or downloaded it.

UKGI is wholly owned by HM Treasury and provides government departments with corporate-finance and corporate-governance expertise. Its work includes advising on public assets, government investments, transactions, and organisations in which the state has a financial or ownership interest.

The sensitivity of the unidentified management information therefore cannot be assessed from the report alone. Even material that does not qualify for mandatory notification to the data regulator may carry commercial, operational, or governmental significance when it concerns public holdings, transactions, board activity, or senior decision-making.

The breach also demonstrates the limits of treating policy compliance as a sufficient control. A rule may have been documented and communicated, but the organisation still needs technical and procedural safeguards that reduce the consequences when a person makes an error or bypasses the expected process.

Public links, misconfigured sharing permissions, incorrectly addressed communications, and files placed in the wrong repository can all create exposure without an external attacker defeating a security product. Those incidents are often categorised as human error, but the duration and reach of the exposure are shaped by platform defaults, access restrictions, monitoring, and approval processes.

UKGI’s decision to involve its Audit and Risk Committee and commission an external review places the response within formal governance rather than leaving it as an operational correction. That creates a documented line between the incident, the organisation’s assessment of its controls, and planned improvements.

The voluntary ICO notification is also notable. Mandatory reporting under UK data-protection law depends on the assessed risk to individuals, but an organisation may still decide that notifying the regulator is appropriate where the circumstances, public role, or uncertainty justify additional scrutiny.

The annual report says most recommendations have been or will be implemented, but does not specify the control changes. Without that detail, it is not possible to assess whether the response focuses on staff training, access governance, data-loss prevention, sharing controls, monitoring, or changes to the handling of management files.

The incident is therefore a confirmed control failure with a bounded public account. A file was exposed, 51 officials’ work details were involved, and policy was not followed. Whether anyone outside the intended audience accessed the information, and what the management material contained, remain undisclosed.

×