UK Government Investments (UKGI), the UK public body that manages state investments, disclosed a data breach after an internal file was left publicly accessible for about 40 hours. The exposed file contained high-level management information along with the names and work email addresses of 51 government officials, and UKGI said the incident was caused by a staff member failing to follow established information security policies.
UKGI said the breach was identified during the 2025–26 financial year, escalated to its board, and voluntarily reported to the UK Information Commissioner’s Office. The agency also commissioned an external security review, which found its response appropriate but recommended stronger security controls and better incident preparedness; UKGI said most of those measures have already been implemented or are planned.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
During the 2025-26 financial year, a UK Government Investments employee failed to follow security policies and left an internal file publicly accessible for around 40 hours. The file contained high-level management information and the names and work email addresses of 51 government officials.
UKGI publicly disclosed the incident in its annual report for the 2025-26 financial year. The disclosure stated that an internal file had been publicly accessible for about 40 hours and exposed 51 officials' names and work email addresses.
UKGI said the overwhelming majority of the external review's recommendations have already been implemented or are scheduled for introduction in the coming months. The measures focus on strengthening controls and incident preparedness.
UKGI brought in external experts to review the incident and its security protocols following the exposure. The review concluded UKGI's response was appropriate and recommended stronger security controls and improved incident preparedness.
After discovering the exposure, UKGI escalated the incident to its board or Audit and Risk Committee and voluntarily reported it to the UK Information Commissioner's Office. UKGI said the incident did not meet the threshold for mandatory ICO notification.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.