Scotland’s prosecution service warned about 300 staff that their information may have been exposed after a cyberattack on a third-party supplier. The Crown Office and Procurator Fiscal Service said the supplier detected suspicious activity on August 5 and that the potentially affected data came from a 2025 online data-maturity assessment organized by the Scottish government. Exposed data may include staff names, roles, and work email addresses; COPFS said its own systems and casework data were not compromised.
Why it matters: Affected staff could now face targeted phishing or impersonation attempts using real work details, even though the exposed data appears limited. Government bodies and public-sector suppliers should verify whether they were involved, notify exposed staff, and watch for follow-on social engineering.
2026.08.14
100% relevant
This article is the first concrete report of the supplier-side breach affecting COPFS staff, establishing the event, the exposed data types, and the affected public-sector organization.
← Back to all stories