Natural Resources Wales (NRW), Wales’ government-sponsored environmental regulator, disclosed special-category personal data for roughly 2,000 current and former employees through a spreadsheet published in response to a Freedom of Information request. The file, uploaded in 2021 and covering staff employed from April 2013 through March 2018, exposed data including ethnicity, disability status, religion or belief, sexual orientation, Welsh-language ability, and caring responsibilities.
NRW said the disclosure resulted from human error and was discovered years after publication. The regulator removed the spreadsheet, obtained confirmation that it had been permanently deleted, and reported the breach to the UK Information Commissioner’s Office; it said it has found no evidence that the information was misused.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Natural Resources Wales published a spreadsheet in response to a Freedom of Information request. The spreadsheet contained equality and diversity-monitoring data for employees who worked for NRW between April 2013 and March 2018.
Years after publication, Natural Resources Wales identified that the spreadsheet had exposed sensitive data relating to approximately 2,000 current and former employees. NRW removed the material, obtained confirmation of permanent deletion, reported the breach to the ICO, and said it found no evidence of misuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcemalware.news
Open sourcenaturalresources.wales
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.