11 de septiembre de 2026

SOCaaS

Centro de Operaciones de Seguridad como servicio

Scottish Govt Suffers Potentially Widening Data Breach


A contractor has leaked Scottish government employees’ personal information, and the full scope of the breach may be far greater than what is currently being reported.

On Aug. 13, Scotland’s Crown Office and Procurator Fiscal Service (COPFS) — the government’s public prosecution service and death investigation authority — disclosed that an unidentified external supplier had experienced a data breach. The breach affected some of its employees’ personally identifying information (PII).

According to the disclosure, COPFS participated in an online data maturity assessment organized by the national government and managed by a third party. As if it weren’t punishment enough to have to do a survey, on Aug. 5, the survey issuer noticed «suspicious activity» presumably affecting its internal network, resulting in a loss of government employee data.

The real scope of the breach may yet be larger, too, as other Scottish government agencies likely participated in that same data maturity assessment, which was part of mandated training across multiple departments, not just COPFS.

Related:Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

Were Any Other Organizations Compromised?

In 2021, the government of Scotland kicked off a «Data Maturity Programme.» Each year, cohorts of government organizations take part in a variety of activities and training. Among the training is, as referenced in the COPFS disclosure, a «Data Maturity Assessment.»

Dark Reading has identified what it believes to be the primary organization administering those assessments: a third-party, UK-based research company called Data Orchard. In a January «Impact Report,» the company boasted that it guided a fifth cohort of public sector organizations through its data maturity assessment process last year, as part of Scotland’s Data Maturity Programme.

As of the time of publication, Data Orchard has not publicly been identified as the source of COPFS’s data leak. It’s also unclear whether COPFS is the only Scottish government organization whose data maturity assessment resulted in a leak, and whether the unnamed third party at fault might have also lost other clients’ data. According to its website, Data Orchard has recently worked with a variety of large organizations, including the World Wildlife Fund (WWF) and the government of Wales.

Dark Reading has reached out to Data Orchard and multiple representatives of the Scottish government for more information on this story, and will update this article if it receives any responses.

COPFS admitted to losing employee data, including names, roles, and work email addresses. Information relating to its cases, victims, and witnesses were unaffected.

Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

In an email, a COPFS representative told Dark Reading that the total number of affected individuals was around 300, and added that IP addresses were not among the data lost.

Boris Cipot, principal security engineer at Black Duck, warns that even if only a few hundred employees lost limited kinds of PII, the risk to Scotland’s government is still serious. «Even seemingly limited employee information can become valuable reconnaissance data,» he explains. «One realistic attack scenario is highly targeted phishing. An attacker who knows a person’s name, role, and government email address can craft convincing messages that appear to come from internal departments, trusted suppliers, or government partners.»

Attackers can build complex campaigns off of even one convincing phishing event.

«The fact that only a few hundred employees were affected should not be used to downplay the risk,» Cipot notes. «Security incidents are not always about volume. It often takes only one compromised employee account to provide an attacker with a foothold into the broader environment.»

How Governments Can Manage Vendor Risk

In general, governments manage massive fleets of third-party contractors. It’s why, so often, breaches of government data and systems stem from incidents at private companies.

Related:Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The issue, says SecurityScorecard threat researcher Cory Kennedy, is that «most vendor vetting in Europe and North America still runs on a point-in-time model. A questionnaire at onboarding, a SOC 2 or ISO 27001 certificate attached, then nothing meaningful for a year. That snapshot goes stale immediately. COPFS is the textbook version: the exposure sat with a survey vendor hired for a one-off assessment, exactly the kind of peripheral supplier that never makes it onto anybody’s continuous monitoring list.»

Improvement isn’t going to come from more paperwork, he says.

«It’s about moving from annual attestation to continuous outside-in monitoring of the supplier’s live attack surface, and pushing that visibility past direct vendors into their dependencies,» Kennedy explains. «NIS2 and DORA are already pulling Europe in that direction. The shift that matters is treating supplier risk as a real-time threat problem.»

Cipot concurs. «My view is that organizations often place too much confidence in the initial assessment process,» he says. «A vendor may pass every compliance review and still suffer a breach months later.»





Este contenido de ciberseguridad nos ha llegado de: DarkReading

Podrás encontrar la noticia original en el siguiente enlace: https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office