A Survey Company May Have Leaked Scottish Government Workers' Personal Details
A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

Key points
- Scotland's Crown Office and Procurator Fiscal Service (COPFS), the country's public prosecution and death-investigation authority, disclosed a data breach on 13 August.
- Roughly 300 government employees had names, job titles, and work email addresses exposed.
- The breach traces to an unnamed third-party contractor that ran a compulsory government training survey.
- Multiple Scottish government departments took part in the same survey programme, meaning the total number of people affected could be far higher.
- No case files, victim details, or witness information were exposed.
A contractor hired to run a routine government training exercise lost personal details belonging to staff at Scotland's most important legal agency, and the damage may stretch well beyond the 300 employees confirmed so far.
Scotland's Crown Office and Procurator Fiscal Service, known as COPFS, is the agency that decides who gets prosecuted in Scotland and investigates sudden or suspicious deaths. On 13 August it admitted that an outside supplier had suffered a data breach, meaning criminals or unauthorised people gained access to data the supplier was holding. Specifically, the supplier had been running a "Data Maturity Assessment," which is a survey-based exercise where organisations score how well they handle data. The COPFS disclosure said that on 5 August the unnamed supplier spotted "suspicious activity" on its systems.
What information was taken?
Employee names, job roles, and work email addresses were exposed. That is the confirmed list. Case records, victim details, and witness information were not affected.
Three hundred people sounds like a small number. Boris Cipot, a senior security engineer at software-security firm Black Duck, disagrees that it should be treated as minor. Even a name and a work email address is enough for criminals to run a convincing phishing attack, where a fake email is crafted to look like it comes from a trusted government colleague or supplier. "It often takes only one compromised employee account to provide an attacker with a foothold into the broader environment," Cipot said.
Could more agencies be affected?
Almost certainly yes. The Data Maturity Assessment is part of a wider Scottish government programme running since 2021. Multiple departments across the public sector take part each year, not just COPFS. That means the unnamed contractor likely held employee data from a range of agencies, all of which could be sitting in the same breached system.
Dark Reading, which broke the story, believes the contractor involved may be Data Orchard, a UK-based research company whose own published reports describe running exactly this kind of programme for Scottish public bodies. Data Orchard has not been publicly named by the Scottish government, and the company had not responded to press enquiries at the time of writing.
Why does a survey company have government employee data at all?
This is the failure mode that keeps appearing in breach post-mortems. Governments use enormous numbers of outside contractors. Many of those contractors, like a survey firm hired for a one-off assessment, never receive sustained security scrutiny after the initial contract is signed.
Cory Kennedy, a researcher at security ratings firm SecurityScorecard, put it plainly: "The exposure sat with a survey vendor hired for a one-off assessment, exactly the kind of peripheral supplier that never makes it onto anybody's continuous monitoring list."
| Detail | Confirmed fact |
|---|---|
| Organisation affected | COPFS, Scotland |
| Disclosure date | 13 August |
| Breach detected | 5 August |
| Employees affected | Approx. 300 |
| Data exposed | Names, roles, work email addresses |
| Data NOT exposed | Case files, victim or witness details |
If you are a Scottish government employee, check your work inbox carefully for emails that seem slightly off, even from addresses that look official. Phishing emails built on real names and real roles are harder to spot than generic scams.
One-time vendor vetting is not vendor security. If your organisation hands personal data to a contractor and then stops watching, the risk does not stop with them.



