Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Scottish prosecutors cast eye over leaky supplier after staff data exposed

Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected

Scottish prosecutors cast eye over leaky supplier after staff data exposed

Scotland's public prosecution service has informed over 300 staff members that their personal data may have been compromised in a cyberattack on one of its suppliers. The Crown Office and Procurator Fiscal Service (COPFS) announced the incident on Thursday, stating that an unidentified third-party supplier discovered suspicious activity on August 5 and initiated an investigation.

The COPFS emphasized that their own systems remained untouched by the breach, which pertains to data supplied for an online data maturity assessment conducted by the prosecution service last year. The Scottish government organized this assessment, which was managed by the implicated supplier. COPFS disclosed that the potentially exposed information includes only employment-related details such as staff names, roles, and work email addresses.

A COPFS spokesperson confirmed that the affected data does not pertain to casework and does not encompass sensitive or confidential case information, thereby not impacting the prosecution service's operations. Colleagues have been reminded of guidance on responding to phishing or scam attempts arising from this third-party breach.

The supplier has taken measures to secure its systems and is continuing its investigation into the intrusion and the extent of accessed information. COPFS pledged to provide additional updates should significant new information arise. The connection between this incident and the recent exploitation of a zero-day vulnerability in business intelligence platform Metabase remains uncertain, as the Scottish government declined to confirm whether the implicated supplier utilized the software.

Metabase reported this month about the exploitation of a previously unknown vulnerability in its cloud service, which could enable attackers to gain administrator access and access connected databases.

Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech