UK government investment arm cops to 40-hour leak of officials' contact details
Employee failed to follow security policy, leaving internal management file open to the public
The UK government's financial advisory firm, UK Government Investments (UKGI), has acknowledged a security lapse in which an employee inadvertently left sensitive information publicly accessible for around 40 hours. This breach, detailed in UKGI's annual report, occurred during the 2025-26 financial year and involved a staff member's failure to follow established information security protocols.
The exposed document included names and work email addresses of 51 government officials, as well as "high-level management information."
UKGI, a Treasury-owned organization that advises ministers on various financial matters, voluntarily reported the incident to the UK's Information Commissioner's Office (ICO) despite it falling below the mandatory notification threshold. The organization also informed its Audit and Risk Committee and commissioned an external review of the breach.
However, the report provides limited information regarding the extent and specifics of the incident, such as the exact timing, location of the file, and whether any unauthorized access or downloads occurred.
The review concluded that UKGI's response to the breach was appropriate and recommended further enhancements to its security controls and incident preparedness. According to the report, "the overwhelming majority" of these recommendations have either been implemented or are scheduled to be introduced in the coming months. This incident occurs amid a year when UKGI has been involved in significant commercial transactions, including the final sale of the government's remaining NatWest shares, advising on financing for small modular reactors, and supporting large capital raises for Eutelsat and Royal Mail.
The Register has reached out to UKGI for additional information, including details about the additional information contained in the leaked file, the specifics of how the file was publicly accessible, whether there is any evidence of any access to the file during the exposure period, and what new safeguards have been introduced since the breach.
The extent of the impact on the officials and the public depends on further disclosure from UKGI. The ICO has confirmed that they are assessing the information provided by UKGI regarding the incident.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.