Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

A third-party data breach at a UK-based research firm, Data Orchard, compromised Scottish government employee PII via a "Data Maturity Assessment" survey administered as part of a national program. The attack vector was a compromise of the third-party supplier's internal network, and the scope of the breach is potentially widening as multiple government agencies used the same service. No technical vulnerability details, CVSS score, affected software versions, patches, or workarounds are provided in the article.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBERSECURITY OPERATIONS CYBER RISK DATA PRIVACY NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, Asia Pacific, Europe, and Latin America. Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well. Nate Nelson,Contributing Writer August 14, 2026 4 Min Read SOURCE: STEPHENBRIDGER VIA GETTY IMAGES A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator Fiscal Service (COPFS) — the government's public prosecution service and death investigation authority — disclosed that an unidentified external supplier had experienced a data breach. The breach affected some of its employees' personally identifying information (PII). According to the disclosure, COPFS participated in an online data maturity assessment organized by the national government and managed by a third party. As if it weren't punishment enough to have to do a survey, on Aug. 5, the survey issuer noticed "suspicious activity" presumably affecting its internal network, resulting in a loss of government employee data. The real scope of the breach may yet be larger, too, as other Scottish government agencies likely participated in that same data maturity assessment, which was part of mandated training across multiple departments, not just COPFS. Related:Long-running Data Theft Campaign Targeting Salesforce, ServiceNow Were Any Other Organizations Compromised? In 2021, the government of Scotland kicked off a "Data Maturity Programme." Each year, cohorts of government organizations take part in a variety of activities and training. Among the training is, as referenced in the COPFS disclosure, a "Data Maturity Assessment." Dark Reading has identified what it believes to be the primary organization administering those assessments: a third-party, UK-based research company called Data Orchard. In a January "Impact Report," the company boasted that it guided a fifth cohort of public sector organizations through its data maturity assessment process last year, as part of Scotland's Data Maturity Programme. As of the time of publication, Data Orchard has not been publicly identified as the source of COPFS's data leak. It's also unclear whether COPFS is the only Scottish government organization whose data maturity assessment resulted in a leak, and whether the unnamed third party at fault might have also lost other clients' data. According to its website, Data Orchard has recently worked with a variety of large organizations, including the World Wildlife Fund (WWF) and the government of Wales. Dark Reading has reached out to Data Orchard and multiple representatives of the Scottish government for more information on this story, and will update this article if it receives any responses. Scottish Legal Agency's Employee Data Leaked COPFS admitted to losing employee data, including names, roles, and work email addresses. Information relating to its cases, victims, and witnesses were unaffected. Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition In an email, a COPFS representative told Dark Reading that the total number of affected individuals was around 300, and added that IP addresses were not among the data lost. Boris Cipot, principal security engineer at Black Duck, warns that even if only a few hundred employees lost limited kinds of PII, the risk to Scotland's government is still serious. "Even seemingly limited employee information can become valuable reconnaissance data," he explains. "One realistic attack scenario is highly targeted phishing. An attacker who knows a person's name, role, and government email address can craft convincing messages that appear to come from internal departments, trusted suppliers, or government partners." Attackers can build complex campaigns off of even one convincing phishing event. "The fact that only a few hundred employees were affected should not be used to downplay the risk," Cipot notes. "Security incidents are not always about volume. It often takes only one compromised employee account to provide an attacker with a foothold into the broader environment." How Governments Can Manage Vendor Risk In general, governments manage massive fleets of third-party contractors. It's why, so often, breaches of government data and systems stem from incidents at private companies. Related:Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The issue, says SecurityScorecard threat researcher Cory Kennedy, is that "most vendor vetting in Europe and North America still runs on a point-in-time model. A questionnaire at onboarding, a SOC 2 or ISO 27001 certificate attached, then nothing meaningful for a year. That snapshot goes stale immediately. COPFS is the textbook version: the exposure sat with a survey vendor hired for a one-off assessment, exactly the kind of peripheral supplier that never makes it onto anybody’s continuous monitoring list." Improvement isn't going to come from more paperwork, he says,. "It’s about moving from annual attestation to continuous outside-in monitoring of the supplier’s live attack surface, and pushing that visibility past direct vendors into their dependencies," Kennedy explains. "NIS2 and DORA are already pulling Europe in that direction. The shift that matters is treating supplier risk as a real-time threat problem." Cipot concurs. "My view is that organizations often place too much confidence in the initial assessment process," he says. "A vendor may pass every compliance review and still suffer a breach months later." Read more about: Europe About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article