Scottish prosecutors cast eye over leaky supplier after staff data exposed
Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected
Scotland's Crown Office and Procurator Fiscal Service (COPFS) has alerted 300 staff members that their personal data may have been compromised due to a cyber attack on one of the organization's suppliers. The incident was discovered on August 5, when the supplier identified suspicious activity and initiated an investigation. COPFS clarified that their own systems remained untouched by the breach.
The affected supplier was tasked with conducting an online data maturity assessment for the Scottish government last year, which is where the potentially exposed information resides. This data pertains to staff employment details, such as names, job roles, and email addresses. COPFS assured that the breach pertains to non-sensitive information and does not impact the prosecution service's ongoing work.
The affected staff have been informed of the necessary precautions to take against potential phishing or scam attempts arising from this third-party breach. The supplier has since fortified its systems and is continuing its investigation into the incident. COPFS has not yet disclosed any significant new information and will update the public accordingly.
The connection between this breach and the recent exploitation of a zero-day vulnerability in Metabase remains unclear. Metabase reported a recent zero-day exploit in its cloud service, which could have granted attackers administrator access and access to connected databases. However, it is currently unknown if the affected supplier utilized Metabase's software.
The supplier breach has left numerous questions unanswered regarding the perpetrator and the extent of their access.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.