COPFS, Data

COPFS Data Breach Exposes 300 Employees' Personal Details

Published on 08/14/2026 at 21:37 | Redaktion boerse-global.de

Scotland's prosecution service has confirmed a data security incident affecting around 300 employees, after a third-party contractor mishandled personal information. The breach has reignited concerns…

Scotland's prosecution service has confirmed a data security incident affecting around 300 employees, after a third-party contractor mishandled personal information. The breach has reignited concerns…
COPFS Data Breach Exposes 300 Employees' Personal Details Illustration mit AI erstellt übermittelt durch boerse-global.de

Scotland's prosecution service has confirmed a data security incident affecting around 300 employees, after a third-party contractor mishandled personal information. The breach has reignited concerns about the risks external suppliers pose when handling sensitive government data.

What Happened at COPFS

The Crown Office and Procurator Fiscal Service (COPFS) disclosed the incident on August 13, 2026, after suspicious activity was detected on August 5. The breach originated with a supplier carrying out a data maturity assessment for the Scottish prosecution service.

The exposed information included employees' names, professional roles, and work email addresses. Officials have stressed that COPFS internal systems were not directly breached, and no sensitive data relating to legal cases, victims, or witnesses was compromised.

While the government has not formally confirmed which contractor was responsible, industry reports suggest the firm Data Orchard may have been involved in the assessment.

Phishing Risk to Government Staff

Cybersecurity experts have warned that, although the leaked data is limited to employment details, it significantly increases the risk of targeted phishing attacks against government personnel. There are also concerns the breach could have wider implications for other agencies participating in the same Data Maturity Programme.

The incident highlights a growing vulnerability: external suppliers increasingly handle sensitive government data, yet their security practices may not always match public-sector standards.

Advertisement

Data incidents like this are a reminder that protecting sensitive information starts with strong internal procedures. For workplace safety and compliance, the same principle applies — having the right documentation in place can prevent costly oversights. A free Risk Assessment Toolkit provides 41 ready-to-use templates and checklists to help you manage workplace risks effectively. Download the free Risk Assessment Toolkit

Scotland's Wider Data Security Problems

The COPFS disclosure follows a series of reports exposing data management failures within the Scottish Government. Between January 2025 and June 2026, the government reported 78 electronic devices as lost or stolen.

That inventory included 57 mobile phones and 21 laptops, only one of which was recovered. The replacement cost was estimated at approximately £28,700. Notably, none of the losses were reported to the Information Commissioner's Office (ICO), the UK's independent data protection regulator.

In a separate ruling, the ICO found that the Scottish Government breached data protection laws by disclosing the identity of Martin Gallagher, a lead campaigner in a pension dispute. That case is linked to the ongoing McCloud remedy process — a £1.7 billion programme affecting roughly 215,000 pensioners. Recent data showed only 59,000 remedy statements had been issued by the March 31 deadline.

Health Sector Under Scrutiny

Scotland's data security practices face further scrutiny in the health sector. Authorities are investigating unauthorised access to medical records at NHS Tayside, involving the records of a nine-year-old murder victim. An insider threat is suspected as the cause.

Advertisement

When organisations face scrutiny over compliance failures, having robust health and safety documentation can make all the difference. Over 37,000 UK companies already use a free Health & Safety Toolkit with ready-made risk assessments and checklists covering key regulations like COSHH and PUWER. Get the free Health & Safety Toolkit

Meanwhile, NHS Blood and Transplant has launched an investigation into the use of unencrypted pagers to transmit sensitive patient data. The practice has since been stopped, but the ICO is examining how patient names, dates of birth, and organ types were handled over the unsecured network. Similar pager security concerns have led other services, such as the North West Ambulance Service, to withdraw the technology entirely.

Disclaimer...

en | boerse | 69951158 |