Scotland's Crown Office and Procurator Fiscal Service (COPFS) said a cyber incident at an unnamed third-party supplier may have exposed personal information belonging to about 300 staff members. The compromised data was linked to an online government data maturity assessment and included employee names, roles, and work email addresses. COPFS said its own systems were not breached and that the incident did not affect operations or expose sensitive casework, victim, witness, or other confidential prosecution data.
The supplier detected suspicious activity on August 5 and launched an investigation, while COPFS said the full scope of the breach remains under review. Reporting indicates the impact could extend beyond COPFS because multiple Scottish government bodies may have participated in the same assessment program. The supplier has reportedly taken steps to secure its systems, but the intrusion method has not been confirmed; one report noted a possible, unverified link to recent exploitation of a Metabase cloud-service zero-day.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
COPFS disclosed that a cyber incident at an external supplier may have exposed employment-related information for around 300 staff, including names, roles, and work email addresses. COPFS said its own systems were not compromised and that case, victim, witness, and other sensitive prosecution data were unaffected.
The unnamed third-party supplier detected suspicious activity affecting its internal network and launched an investigation. The activity reportedly resulted in loss of government employee data.
The Scottish government's Data Maturity Programme began in 2021 and includes yearly cohorts and a Data Maturity Assessment involving public sector organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcetheregister.com
Open sourcecopfs.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.