TechNewsReel
Live

Scottish Prosecution Service Probes Data Leak at Third-Party Supplier

Personal details of approximately 300 COPFS staff were exposed through a government-organized data maturity survey.

TechNewsReel Newsroom · August 14, 2026

The Crown Office and Procurator Fiscal Service (COPFS) is investigating a data breach after the personal information of its employees was exposed via a third-party supplier. The leak was identified after an external party detected suspicious activity involving the prosecution service's personnel data.

According to reports from The Register, the breach did not result from a direct attack on COPFS internal systems. Instead, the exposure occurred through an external supplier managing a public sector data maturity survey organized by the Scottish Government. The leaked dataset includes the names, professional roles, and work email addresses of approximately 300 COPFS staff members.

The vulnerability of legal data

As the independent public prosecution service for Scotland, COPFS is tasked with the critical responsibilities of prosecuting crime and investigating sudden deaths. Because of the sensitive nature of prosecutorial work, the security of its personnel data is considered high-risk. The reliance on external vendors for government-wide initiatives, such as the data maturity survey in this instance, introduces a secondary attack surface that can bypass the primary security perimeters of the agency itself.

Risks to prosecution officials

The exposure of specific professional roles and work emails creates a significant security opening for malicious actors. Security experts note that such data is frequently used to craft highly targeted phishing campaigns and social engineering attacks. For officials within a prosecution service, these risks are amplified, as targeted harassment or attempts to compromise the integrity of legal proceedings could follow the initial data theft.

Oversight of government suppliers

This incident raises urgent questions regarding the vetting processes and security standards required of government suppliers within the Scottish legal system. While the COPFS is currently investigating the extent of the exposure, the breach highlights a systemic vulnerability where the security of a high-profile public body is only as strong as the weakest link in its supply chain. It remains to be seen whether the Scottish Government will implement stricter auditing requirements for third-party vendors handling public sector personnel data.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.