NATURAL Resources Wales (NRW) has confirmed a data breach caused by human error, with sensitive personal information exposed after a spreadsheet containing employee details was inadvertently published on NRW’s website. The incident was reported to have affected current and former NRW staff.
The dataset potentially revealed a range of sensitive attributes, including ethnicity, disability status, religion, sexual orientation, and caring responsibilities. Additional information that may have been disclosed included Welsh language ability and other equality monitoring data. NRW indicated that not every category applied to every person, but the breach nonetheless concerns individuals who worked for NRW between April 2013 and March 2018.
The article notes that the breach’s disclosure occurred due to an administrative mistake resulting in the public posting of the spreadsheet. It does not detail NRW’s immediate remedial steps or any notification to affected individuals beyond the public revelation of the breach. The reporting cites Nation[.]Cymru as the source for the specifics on which data fields were exposed and the timespan of employment affected.
Given the sensitivity of the data, affected staff may be exposed to risk related to privacy and discrimination, though the article stops short of describing any confirmed exploitation or identity misuse. No CVEs, software versions, or technical indicators are provided in the supplied content.