A data breach affecting the Scottish government's Crown Office and Procurator Fiscal Service (COPFS)has resulted from a contractor's leak of personal information of government employees. The breach was linked to an online data maturity assessment facilitated by a third-party supplier, raising concerns that other agencies may also be affected. Approximately 300 individuals' details, including names and email addresses, were disclosed, although sensitive case-related information was not compromised.
Experts warn that even limited employee information can enable targeted phishing attacks, emphasizing the need for improved vendor risk management. Continuous monitoring of contractors and their systems is recommended as a more effective strategy than one-time assessments.