Violazione presso il Crown Office scozzese: esposti i dati di circa 300 dipendenti
Data Breaches

Illustrative image generated with AI

Breach at Scotland’s Crown Office Exposes Data of Approximately 300 Employees

COPFS reports a data breach affecting 300 employees via an external provider. Exposed data includes names, job titles, and emails, raising phishing risks.

Text generated by artificial intelligence, published without human review. AI transparency

Incident Originated with an External Provider

The Crown Office and Procurator Fiscal Service (COPFS), Scotland’s public prosecution and death investigation service, reported a potential personal data breach on August 13.

The incident reportedly did not directly affect COPFS systems. Instead, the likely entry point was an external provider hired to manage an online data maturity assessment conducted as part of a training programme for various public-sector organisations.

The organisation that issued the questionnaire detected suspicious activity on August 5. The incident appeared to affect the provider’s internal network and resulted in the loss of information relating to government employees.

COPFS estimates that approximately 300 people were affected. The scope could be broader, however: the assessment formed part of the Scottish Government’s Data Maturity Programme, launched in 2021 and opened each year to groups of public-sector organisations.

It is not known whether COPFS is the only Scottish body affected. It also remains unclear whether the same provider lost data belonging to other customers.

What Information Was Exposed

The potentially compromised information concerns employee identification and organisational details:

  • name;
  • job title;
  • work email address.

IP addresses do not appear to have been included in the stolen data. COPFS also stated that the incident did not involve information relating to court proceedings, victims or witnesses.

Based on the available information, there is therefore no evidence that court files or operational data managed by the service were accessed. The main risk involves identifying employees, understanding their roles and contacting them through official channels.

Even a limited set of data can be valuable to an attacker. A job title combined with a government email address makes it possible to craft more credible messages than a generic phishing campaign. An email addressed to a real person and tailored to their responsibilities may increase the likelihood that a link will be opened or a request will appear legitimate.

Provider Has Not Been Formally Named

COPFS has not publicly identified the company responsible for the assessment. Data Orchard, a UK-based research company, has been identified as a possible programme administrator.

On its website, Data Orchard describes its participation in a fifth cohort of public-sector organisations involved in a data maturity assessment programme. This does not formally confirm that the company was the provider involved in the breach.

The company has also reportedly worked with large organisations, including the World Wildlife Fund and the Welsh Government. It is not known whether data belonging to those organisations was involved in the incident.

Other questions also remain unanswered, including which systems were compromised, how long the attacker had access to the network and whether data belonging to organisations other than COPFS was copied. No specific attack technique has been disclosed, and no formal severity rating has been assigned.

Why Names and Job Titles Can Become an Operational Risk

The combination of a name, job title and work email address provides useful information for reconnaissance. An attacker could use it to impersonate a colleague, internal department, supplier or institutional partner.

The risk increases when a message directs the recipient to a fake login portal, asks them to review a document or creates a sense of urgency. In these scenarios, the employee is not necessarily the ultimate target: their account may become the initial access point to broader resources.

The breach does not demonstrate that a COPFS account was compromised. However, the exposed data could facilitate follow-on attacks against affected staff, particularly when combined with publicly available information about their responsibilities and the organisation’s structure.

For this reason, the number of people affected is not enough to measure the impact. Three hundred well-profiled professional identities can provide a useful target surface for tailored campaigns, even without passwords, financial data or court files.

The Problem with “Peripheral” Suppliers

The case highlights a common risk in third-party risk management programmes. Organisations tend to focus controls on strategic suppliers and continuously used services, while platforms used for questionnaires, training or assessments may receive less scrutiny.

According to Cory Kennedy, a threat intelligence researcher at SecurityScorecard, many companies still rely on initial checks, questionnaires and SOC 2 or ISO 27001 certifications. After onboarding, however, monitoring may be significantly reduced or discontinued.

A certification or positive assessment describes a situation observed at a specific point in time. It does not guarantee that a provider will remain secure months later, or that all of its dependencies will maintain the same level of security.

Kennedy recommends continuous external monitoring of the actual attack surface, including the dependencies of direct suppliers. NIS2 and DORA are helping shift the European framework towards more dynamic third-party risk management, but their implementation does not automatically eliminate gaps in internal processes.

Boris Cipot, principal security engineer at Black Duck, notes that passing initial compliance checks does not prevent a provider from being compromised later. Pre-contract due diligence therefore cannot be treated as a permanent guarantee.

What COPFS and Affected Individuals Should Do

COPFS and the provider have not disclosed any patches, credential revocations, technical blocks or other containment measures already implemented. The incident’s final scope remains unclear.

In the meantime, the organisations involved should:

  • notify affected staff about the potential fraudulent use of their information;
  • strengthen monitoring of emails sent to exposed employees;
  • review authentication controls and account protections;
  • implement additional checks for anomalous access and credential-harvesting attempts;
  • reassess occasional suppliers, not only those considered strategic;
  • extend the analysis to the technical dependencies of direct suppliers;
  • conduct periodic reviews rather than relying solely on onboarding checks.

Employees should be wary of unexpected requests involving passwords, documents, payments or access to internal portals, even when the sender appears to belong to a familiar department. When in doubt, the request should be verified through an independent channel.

The priority remains determining whether the incident affected other organisations participating in the Data Maturity Programme and which data was actually copied. Until then, the figure of approximately 300 employees represents an estimate of the known impact, not necessarily the maximum extent of the breach.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsdata breachScotlandCrown OfficeCOPFSemployee dataphishingthird-party riskexternal provider
Back to home