UK Government Investments said an internal file containing the names and work email addresses of 51 government officials was left publicly accessible for around 40 hours. The Treasury-owned advisory body said the exposure happened in the 2025-26 financial year after an employee failed to follow information-security policy. UKGI said it reported the incident to the Information Commissioner's Office and commissioned an external review, but did not disclose where the file was hosted or whether anyone accessed it.
Why it matters: Even limited government contact data can be used for phishing, impersonation, or targeting officials. Public-sector organizations should review file-sharing controls and employee handling of sensitive documents, while affected staff should be alert for suspicious messages.
2026.08.03
100% relevant
This article establishes a distinct newly disclosed government data exposure incident centered on UK Government Investments' accidental public file exposure.
← Back to all stories